Tagged “ghsa”
CVEs tagged ghsa, newest first.
3900 CVEsRSS
CVE-2026-53765Medium· 6.1Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-54235Medium· 6.5vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
CVE-2026-12491Medium· 4.8vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-53923High· 7.5vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
CVE-2026-54236Medium· 5.3PoCvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVE-2026-54233Medium· 6.5vLLM: OOM Denial of Service via Audio Decompression Bomb
vLLM: OOM Denial of Service via Audio Decompression Bomb
CVE-2026-53927MediumNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
CVE-2026-53928MediumNocoDB: Refresh Tokens Persist Through Password Recovery
NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-53929MediumNocoDB: Stored Cross-Site Scripting via Secure Attachment
NocoDB: Stored Cross-Site Scripting via Secure Attachment
CVE-2026-53930MediumNocoDB: Server-Side Request Forgery via Base Migration URL
NocoDB: Server-Side Request Forgery via Base Migration URL
CVE-2026-53931MediumNocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-54006Medium· 4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
CVE-2026-54007HighOpen WebUI: Cross-origin postMessage confirmation bypass via action:submit
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-54008High· 8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
CVE-2026-54009Medium· 6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2026-54010High· 8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-54012High· 7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-54013High· 7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
CVE-2026-54014Medium· 4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
CVE-2026-54015Medium· 6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
CVE-2026-54016Medium· 4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
CVE-2026-53840High· 7.1OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
CVE-2026-54017High· 7.7Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
CVE-2026-54018High· 7.7Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
CVE-2026-54019Medium· 6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-54021Medium· 6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
CVE-2026-54022Medium· 5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVE-2026-54316MediumPoCClaude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch