Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2026-49268HighPoCApache Shiro: LDAP DN Injection in DefaultLdapRealm
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
GHSA-6v84-v468-3c7fCritical· 9.8Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs
GHSA-rmpp-8wf5-xx5qCritical· 9.8Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
CVE-2026-55748Medium· 6.0OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…
GHSA-7f79-rvx6-vxc4Critical· 9.8Duplicate Advisory: Picklescan does not block ctypes
Duplicate Advisory: Picklescan does not block ctypes
GHSA-5rph-q42j-36j9Critical· 9.8Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
CVE-2025-26240High· 8.4PoCpdfkit: Path traversal in from_string
pdfkit: Path traversal in from_string
GHSA-5gp7-4733-2w2vHigh· 8.8Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
GHSA-82fg-2r99-h7v6Critical· 10.0Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
GHSA-5v23-73v4-w2fpHigh· 7.5Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
CVE-2026-12515Medium· 4.3katello: missing repository authorization in content_uploads exposes cross-product content existence
katello: missing repository authorization in content_uploads exposes cross-product content existence
GHSA-j6c9-qvp8-699fCritical· 9.8Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
GHSA-cc5p-54x3-hcf8HighDuplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
GHSA-4mpj-78p6-rj59Critical· 9.8Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
CVE-2026-48591Mediumearmark: Stored XSS via unescaped HTML attribute values
earmark: Stored XSS via unescaped HTML attribute values
CVE-2026-55405High· 7.6LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
CVE-2026-55409High· 7.6Filament: Disabled RichEditor field state can be used for XSS
Filament: Disabled RichEditor field state can be used for XSS
CVE-2026-55760High· 7.5handlebars.java FileTemplateLoader Path Traversal
handlebars.java FileTemplateLoader Path Traversal
CVE-2026-55450Critical· 9.3PoCLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-55470High· 7.5HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
CVE-2026-55471CriticalHAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
CVE-2026-55518Critical· 9.6Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
CVE-2026-55590MediumCakePHP Authentication: Open redirect weakness via backslash bypass
CakePHP Authentication: Open redirect weakness via backslash bypass
CVE-2026-53870Medium· 5.5Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
CVE-2026-53869High· 7.5Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
CVE-2026-11407High· 7.2Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
CVE-2026-6734High· 7.5undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client …
CVE-2026-9697High· 7.4undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)
A flaw was found in undici. When undici's ProxyAgent is configured with a SOCKS5 proxy Uniform Resource Identifier (URI), it silently ignores Transport Layer Security (TLS) options, such as custom Certificate Authorities (CAs). This allows…
CVE-2026-56301Medium· 5.5Nuxt dev server vite-node IPC socket is world-connectable on Linux
Nuxt dev server vite-node IPC socket is world-connectable on Linux