Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-54776Medium· 4.4CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVE-2026-54777Medium· 6.5CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVE-2026-54778Medium· 6.2CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVE-2026-54779Medium· 5.9CoreWCF: SAML token replay protection is inoperative
CoreWCF: SAML token replay protection is inoperative
CVE-2026-54780Low· 3.7CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-54781High· 7.4CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVE-2026-54782Critical· 10.0CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVE-2026-54783High· 7.4CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CVE-2026-54784High· 7.4CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
GHSA-v52w-28xh-v562HighKozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
CVE-2026-54900HighPoCOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-54901HighOj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
CVE-2026-54902HighOj: Use-After-Free in Oj::Parser SAJ Long Key Callback
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
CVE-2026-54903HighOj: Integer Overflow in Oj.load 2GB String Handling
Oj: Integer Overflow in Oj.load 2GB String Handling
CVE-2026-54904HighConcurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
CVE-2026-54905LowConcurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
CVE-2026-54906LowConcurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
CVE-2026-54911Medium· 6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
GHSA-x845-2f78-7v36High· 8.6Blocky DNSSEC validation bypass and validation-cache scope pollution
Blocky DNSSEC validation bypass and validation-cache scope pollution
CVE-2026-55849High@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
GHSA-wfqx-gjrf-g28rCritical· 9.0Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
CVE-2026-11769MediumGrafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
CVE-2026-54074High· 7.8@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
CVE-2026-55791CriticalCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
GHSA-78vr-q6cf-c7p6MediumCraft Commerce: Partial Payment Amount Without Lower Bound Validation
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
GHSA-8823-qg2x-pv9fHigh· 7.5Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit
Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit
GHSA-p5wc-9w9r-m232High· 7.5Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser
Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser
GHSA-rpj2-4hq8-938gHigh· 7.8VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
CVE-2026-54762High· 8.6Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails