Tagged “ghsa”
CVEs tagged ghsa, newest first.
3900 CVEsRSS
CVE-2026-54324Medium· 6.5Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
CVE-2026-22555High· 8.1Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
CVE-2026-24791High· 8.1Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
CVE-2026-28737High· 8.7Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
CVE-2026-25779MediumGitea: Open Redirect via redirect_to
Gitea: Open Redirect via redirect_to
CVE-2026-9595Medium· 5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
GHSA-x8xr-mj9x-6h7wMedium· 4.8Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-32966Critical· 9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
CVE-2026-32967Critical· 9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CVE-2026-41280Medium· 4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CVE-2026-42357Medium· 6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
CVE-2026-47340Medium· 6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
CVE-2026-50203Critical· 9.1Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
CVE-2026-49268HighPoCApache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
GHSA-6v84-v468-3c7fCritical· 9.8Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
GHSA-rmpp-8wf5-xx5qCritical· 9.8Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
CVE-2026-55748Medium· 6.0OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…
GHSA-7f79-rvx6-vxc4Critical· 9.8Duplicate Advisory: Picklescan does not block ctypes
Duplicate Advisory: Picklescan does not block ctypes
GHSA-5rph-q42j-36j9Critical· 9.8Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
CVE-2025-26240High· 8.4PoCpdfkit: Path traversal in from_string
pdfkit: Path traversal in from_string
GHSA-5gp7-4733-2w2vHigh· 8.8Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
GHSA-82fg-2r99-h7v6Critical· 10.0Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
GHSA-5v23-73v4-w2fpHigh· 7.5Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-12515Medium· 4.3katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: missing repository authorization in content_uploads exposes cross-product content existence
GHSA-j6c9-qvp8-699fCritical· 9.8Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
GHSA-cc5p-54x3-hcf8HighDuplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
GHSA-4mpj-78p6-rj59Critical· 9.8Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
CVE-2026-48591Mediumearmark: Stored XSS via unescaped HTML attribute values
earmark: Stored XSS via unescaped HTML attribute values
CVE-2026-55405High· 7.6LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
CVE-2026-55409High· 7.6Filament: Disabled RichEditor field state can be used for XSS
Filament: Disabled RichEditor field state can be used for XSS