VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3900 CVEsRSS

CVE-2026-54324Medium· 6.5
3mo ago

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.46%via GHSA
CVE-2026-22555High· 8.1
3mo ago

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-24791High· 8.1
3mo ago

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.45%via GHSA
CVE-2026-28737High· 8.7
3mo ago

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-25779Medium
3mo ago

Gitea: Open Redirect via redirect_to

Gitea: Open Redirect via redirect_to

▾ Sunlitgo-gitea · github.com/go-gitea/giteaEPSS 0.34%via GHSA
CVE-2026-9595Medium· 5.3
3mo ago

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

▾ Sunlitwebpack-dev-server · webpack-dev-serverEPSS 0.23%via GHSA
GHSA-x8xr-mj9x-6h7wMedium· 4.8
3mo ago

Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

▾ Sunlitvllm · vllmvia GHSA
CVE-2026-32966Critical· 9.8
3mo ago

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.66%via GHSA
CVE-2026-32967Critical· 9.1
3mo ago

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks

▾ Midnightapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-41280Medium· 4.9
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.54%via GHSA
CVE-2026-42357Medium· 6.5
3mo ago

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.49%via GHSA
CVE-2026-47340Medium· 6.5
3mo ago

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.

▾ Sunlitapache · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.55%via GHSA
CVE-2026-50203Critical· 9.1
3mo ago

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory

Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory

▾ Midnightapache-airflow-providers-sftp · apache-airflow-providers-sftpEPSS 0.88%via OSV
CVE-2026-49268HighPoC
3mo ago

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

▾ Midnightapache · org.apache.shiro:shiro-coreEPSS 0.76%via GHSA
GHSA-6v84-v468-3c7fCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-rmpp-8wf5-xx5qCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-55748Medium· 6.0
3mo ago

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…

▾ Sunlitopenstack · horizonEPSS 0.46%via NVD
GHSA-7f79-rvx6-vxc4Critical· 9.8
3mo ago

Duplicate Advisory: Picklescan does not block ctypes

Duplicate Advisory: Picklescan does not block ctypes

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-5rph-q42j-36j9Critical· 9.8
3mo ago

Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2025-26240High· 8.4PoC
3mo ago

pdfkit: Path traversal in from_string

pdfkit: Path traversal in from_string

▾ Midnightpdfkit · pdfkitEPSS 0.39%via GHSA
GHSA-5gp7-4733-2w2vHigh· 8.8
3mo ago

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-82fg-2r99-h7v6Critical· 10.0
3mo ago

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-5v23-73v4-w2fpHigh· 7.5
3mo ago

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-12515Medium· 4.3
3mo ago

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

▾ Sunlitkatello · katelloEPSS 0.22%via GHSA
GHSA-j6c9-qvp8-699fCritical· 9.8
3mo ago

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-cc5p-54x3-hcf8High
3mo ago

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-4mpj-78p6-rj59Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-48591Medium
3mo ago

earmark: Stored XSS via unescaped HTML attribute values

earmark: Stored XSS via unescaped HTML attribute values

▾ Sunlitearmark · earmarkEPSS 0.19%via GHSA
CVE-2026-55405High· 7.6
3mo ago

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

▾ Twilightlangchain4j · dev.langchain4j:langchain4j-mariadbEPSS 0.47%via GHSA
CVE-2026-55409High· 7.6
3mo ago

Filament: Disabled RichEditor field state can be used for XSS

Filament: Disabled RichEditor field state can be used for XSS

▾ Twilightfilament · filament/formsEPSS 0.28%via GHSA
CVEs tagged “ghsa” — page 116 · VulnSea