VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-jrpc-7vxp-69p6Medium
3mo ago

http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`

http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`

▾ Sunlithttp4k · org.http4k:http4k-corevia GHSA
GHSA-m4w9-hjfw-vwj4High
3mo ago

http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`

http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`

▾ Twilighthttp4k · org.http4k:http4k-corevia GHSA
GHSA-pr33-38xx-6r26Medium
3mo ago

http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default

http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default

▾ Sunlithttp4k · org.http4k:http4k-corevia GHSA
GHSA-c7jm-38gq-h67hMedium
3mo ago

http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments

http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments

▾ Sunlithttp4k · org.http4k:http4k-security-digestvia GHSA
CVE-2026-55185Medium
3mo ago

Open Redirect Bypass in miniflux-v2

Open Redirect Bypass in miniflux-v2

▾ Sunlitv2 · miniflux.app/v2EPSS 0.59%via GHSA
CVE-2026-55187Medium· 5.8
3mo ago

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.38%via GHSA
CVE-2026-55195Medium
3mo ago

py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size

py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size

▾ Sunlitpy7zr · py7zrEPSS 0.32%via GHSA
CVE-2026-55206Medium
3mo ago

py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()

py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()

▾ Sunlitpy7zr · py7zrEPSS 0.32%via GHSA
CVE-2026-55255Critical· 9.9CISA KEVPoC
3mo ago

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

▾ Hadallangflow · langflowEPSS 0.89%via GHSA
CVE-2026-55423Medium· 6.1
3mo ago

Langflow: Logout button does not clear session

Langflow: Logout button does not clear session

▾ Sunlitlangflow · langflowEPSS 0.22%via OSV
CVE-2026-55446High· 7.5
3mo ago

Langflow: Unauthenticated DoS through multipart form boundary file upload

Langflow: Unauthenticated DoS through multipart form boundary file upload

▾ Twilightlangflow · langflowEPSS 0.58%via GHSA
CVE-2026-55447Critical· 9.6
3mo ago

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

▾ Midnightlangflow · langflowEPSS 0.66%via GHSA
CVE-2026-55877Medium· 6.1
3mo ago

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses

▾ Sunlitsymfony · symfony/ux-iconsEPSS 0.34%via GHSA
CVE-2026-55878High· 7.8
3mo ago

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest

▾ Twilightsymfony · symfony/ux-toolkitEPSS 0.19%via GHSA
GHSA-h5jc-78hr-3pc9Low
3mo ago

Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe

Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe

▾ Sunlitsveltia · @sveltia/cmsvia GHSA
GHSA-9c83-rr99-vfwjMedium
3mo ago

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested

▾ Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
GHSA-2fmp-9rvw-hc96High· 7.1
3mo ago

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning

▾ Twilightnetwork-ai · network-aivia GHSA
GHSA-jvcm-f35g-w78pMedium· 6.5
3mo ago

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-mxjx-28vx-xjjjMedium· 5.9
3mo ago

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-6x2m-p4xp-wg22Medium· 5.5
3mo ago

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-48x2-6pr9-2jjfMedium· 6.1
3mo ago

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-xcqx-9jf5-w339High· 7.5
3mo ago

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

▾ Twilightmcp-searxng · mcp-searxngvia GHSA
GHSA-mrvx-jmjw-vggcHigh· 7.1
3mo ago

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`

▾ Twilightmcp-searxng · mcp-searxngvia GHSA
GHSA-97pr-9hgg-3p8rLow
3mo ago

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change

▾ Sunlitparse-server · parse-servervia GHSA
GHSA-6vxv-wg6j-5qwpHigh
3mo ago

Gogs: XSS in .ipynb files renderer due to outdated notebookjs

Gogs: XSS in .ipynb files renderer due to outdated notebookjs

▾ Twilightgogs · gogs.io/gogsvia GHSA
GHSA-6v7p-g79w-8964High· 7.5
3mo ago

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error

▾ Twilightmsgpack · msgpackvia GHSA
GHSA-x26h-xmv8-gxf7High
3mo ago

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

▾ Twilightstigmem-node · stigmem-nodevia GHSA
GHSA-xhv3-q4xx-349rHigh
3mo ago

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

▾ Twilightstigmem-node · stigmem-nodevia GHSA
GHSA-6gqw-jqv7-v88mHigh
3mo ago

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

▾ Twilightstigmem-node · stigmem-nodevia GHSA
GHSA-v3f4-w7r7-v3hmHigh
3mo ago

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

▾ Twilightzenalexa · @zenalexa/uniclivia GHSA
CVEs tagged “ghsa” — page 106 · VulnSea