Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-jrpc-7vxp-69p6Mediumhttp4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
GHSA-m4w9-hjfw-vwj4Highhttp4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`
http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`
GHSA-pr33-38xx-6r26Mediumhttp4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
GHSA-c7jm-38gq-h67hMediumhttp4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
CVE-2026-55185MediumOpen Redirect Bypass in miniflux-v2
Open Redirect Bypass in miniflux-v2
CVE-2026-55187Medium· 5.8Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
CVE-2026-55195Mediumpy7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
CVE-2026-55206Mediumpy7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
CVE-2026-55255Critical· 9.9CISA KEVPoCLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-55423Medium· 6.1Langflow: Logout button does not clear session
Langflow: Logout button does not clear session
CVE-2026-55446High· 7.5Langflow: Unauthenticated DoS through multipart form boundary file upload
Langflow: Unauthenticated DoS through multipart form boundary file upload
CVE-2026-55447Critical· 9.6Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-55877Medium· 6.1symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses
CVE-2026-55878High· 7.8symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
GHSA-h5jc-78hr-3pc9LowSveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
GHSA-9c83-rr99-vfwjMediumMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
GHSA-2fmp-9rvw-hc96High· 7.1Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
GHSA-jvcm-f35g-w78pMedium· 6.5Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
GHSA-mxjx-28vx-xjjjMedium· 5.9Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
GHSA-6x2m-p4xp-wg22Medium· 5.5Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
GHSA-48x2-6pr9-2jjfMedium· 6.1Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
GHSA-xcqx-9jf5-w339High· 7.5SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
GHSA-mrvx-jmjw-vggcHigh· 7.1SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
GHSA-97pr-9hgg-3p8rLowparse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change
GHSA-6vxv-wg6j-5qwpHighGogs: XSS in .ipynb files renderer due to outdated notebookjs
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
GHSA-6v7p-g79w-8964High· 7.5MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
GHSA-x26h-xmv8-gxf7Highstigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
GHSA-xhv3-q4xx-349rHighstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
GHSA-6gqw-jqv7-v88mHighstigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
GHSA-v3f4-w7r7-v3hmHighUni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests