VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-54776Medium· 4.4
3mo ago

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade

▾ SunlitCoreWCF · CoreWCF.UnixDomainSocketEPSS 0.15%via GHSA
CVE-2026-54777Medium· 6.5
3mo ago

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

▾ SunlitCoreWCF · CoreWCF.NetNamedPipeEPSS 0.12%via GHSA
CVE-2026-54778Medium· 6.2
3mo ago

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

▾ SunlitCoreWCF · CoreWCF.UnixDomainSocketEPSS 0.13%via GHSA
CVE-2026-54779Medium· 5.9
3mo ago

CoreWCF: SAML token replay protection is inoperative

CoreWCF: SAML token replay protection is inoperative

▾ SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.43%via GHSA
CVE-2026-54780Low· 3.7
3mo ago

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

▾ SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.24%via GHSA
CVE-2026-54781High· 7.4
3mo ago

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.25%via GHSA
CVE-2026-54782Critical· 10.0
3mo ago

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

▾ MidnightCoreWCF · CoreWCF.PrimitivesEPSS 0.41%via GHSA
CVE-2026-54783High· 7.4
3mo ago

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.19%via GHSA
CVE-2026-54784High· 7.4
3mo ago

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.27%via GHSA
GHSA-v52w-28xh-v562High
3mo ago

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

▾ Twilightkozou · kozouvia GHSA
CVE-2026-54900HighPoC
3mo ago

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling

▾ Midnightoj · ojEPSS 0.43%via GHSA
CVE-2026-54901High
3mo ago

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54902High
3mo ago

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54903High
3mo ago

Oj: Integer Overflow in Oj.load 2GB String Handling

Oj: Integer Overflow in Oj.load 2GB String Handling

▾ Twilightoj · ojEPSS 0.43%via GHSA
CVE-2026-54904High
3mo ago

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`

▾ Twilightconcurrent-ruby · concurrent-rubyEPSS 0.67%via GHSA
CVE-2026-54905Low
3mo ago

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity

▾ Sunlitconcurrent-ruby · concurrent-rubyEPSS 0.15%via GHSA
CVE-2026-54906Low
3mo ago

Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption

▾ Sunlitconcurrent-ruby · concurrent-rubyEPSS 0.25%via GHSA
CVE-2026-54911Medium· 6.5
3mo ago

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

▾ Sunlitujson · ujsonEPSS 0.37%via OSV
GHSA-x845-2f78-7v36High· 8.6
3mo ago

Blocky DNSSEC validation bypass and validation-cache scope pollution

Blocky DNSSEC validation bypass and validation-cache scope pollution

▾ Twilight0xERR0R · github.com/0xERR0R/blockyvia GHSA
CVE-2026-55849High
3mo ago

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

▾ Twilightcyclonedx · @cyclonedx/cyclonedx-npmEPSS 0.24%via GHSA
GHSA-wfqx-gjrf-g28rCritical· 9.0
3mo ago

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

▾ Midnightcrossplane · github.com/crossplane/crossplane/v2via GHSA
CVE-2026-11769Medium
3mo ago

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

▾ Sunlitgrafana · github.com/grafana/grafana-operator/v5EPSS 0.36%via GHSA
CVE-2026-54074High· 7.8
3mo ago

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

▾ Twilighttinacms · @tinacms/cliEPSS 0.25%via GHSA
CVE-2026-55791Critical
3mo ago

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

▾ Midnightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
GHSA-78vr-q6cf-c7p6Medium
3mo ago

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

▾ Sunlitcraftcms · craftcms/commercevia GHSA
CVE-2026-55660High
3mo ago

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

▾ Twilighttinacms · tinacmsEPSS 0.28%via GHSA
GHSA-8823-qg2x-pv9fHigh· 7.5
3mo ago

Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit

Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit

▾ Twilightultimate-sitemap-parser · ultimate-sitemap-parservia GHSA
GHSA-p5wc-9w9r-m232High· 7.5
3mo ago

Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser

Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser

▾ Twilightultimate-sitemap-parser · ultimate-sitemap-parservia GHSA
GHSA-rpj2-4hq8-938gHigh· 7.8
3mo ago

VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files

VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files

▾ Twilightvcrpy · vcrpyvia GHSA
CVE-2026-54762High· 8.6
3mo ago

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

▾ Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.43%via OSV
CVEs tagged “ghsa” — page 105 · VulnSea