VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2026-49268HighPoC
3mo ago

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

Apache Shiro: LDAP DN Injection in DefaultLdapRealm

▾ Midnightapache · org.apache.shiro:shiro-coreEPSS 0.76%via GHSA
GHSA-6v84-v468-3c7fCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-rmpp-8wf5-xx5qCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-55748Medium· 6.0
3mo ago

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…

▾ Sunlitopenstack · horizonEPSS 0.46%via NVD
GHSA-7f79-rvx6-vxc4Critical· 9.8
3mo ago

Duplicate Advisory: Picklescan does not block ctypes

Duplicate Advisory: Picklescan does not block ctypes

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-5rph-q42j-36j9Critical· 9.8
3mo ago

Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2025-26240High· 8.4PoC
3mo ago

pdfkit: Path traversal in from_string

pdfkit: Path traversal in from_string

▾ Midnightpdfkit · pdfkitEPSS 0.39%via GHSA
GHSA-5gp7-4733-2w2vHigh· 8.8
3mo ago

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-82fg-2r99-h7v6Critical· 10.0
3mo ago

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-5v23-73v4-w2fpHigh· 7.5
3mo ago

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-12515Medium· 4.3
3mo ago

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

▾ Sunlitkatello · katelloEPSS 0.22%via GHSA
GHSA-j6c9-qvp8-699fCritical· 9.8
3mo ago

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-cc5p-54x3-hcf8High
3mo ago

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-4mpj-78p6-rj59Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-48591Medium
3mo ago

earmark: Stored XSS via unescaped HTML attribute values

earmark: Stored XSS via unescaped HTML attribute values

▾ Sunlitearmark · earmarkEPSS 0.19%via GHSA
CVE-2026-55405High· 7.6
3mo ago

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector

▾ Twilightlangchain4j · dev.langchain4j:langchain4j-mariadbEPSS 0.47%via GHSA
CVE-2026-55409High· 7.6
3mo ago

Filament: Disabled RichEditor field state can be used for XSS

Filament: Disabled RichEditor field state can be used for XSS

▾ Twilightfilament · filament/formsEPSS 0.28%via GHSA
CVE-2026-55760High· 7.5
3mo ago

handlebars.java FileTemplateLoader Path Traversal

handlebars.java FileTemplateLoader Path Traversal

▾ Twilightgithub · com.github.jknack:handlebarsEPSS 0.53%via GHSA
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-55470High· 7.5
3mo ago

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVE-2026-55471Critical
3mo ago

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

▾ Midnightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesEPSS 0.57%via GHSA
CVE-2026-55518Critical· 9.6
3mo ago

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

▾ Midnightavo · avoEPSS 0.45%via GHSA
CVE-2026-55590Medium
3mo ago

CakePHP Authentication: Open redirect weakness via backslash bypass

CakePHP Authentication: Open redirect weakness via backslash bypass

▾ Sunlitcakephp · cakephp/authenticationEPSS 0.49%via GHSA
CVE-2026-53870Medium· 5.5
3mo ago

Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)

Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)

▾ Sunlithermes-agent · hermes-agentEPSS 0.15%via GHSA
CVE-2026-53869High· 7.5
3mo ago

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

▾ Twilighthermes-agent · hermes-agentEPSS 0.81%via GHSA
CVE-2026-11407High· 7.2
3mo ago

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed

▾ Twilightpimcore · pimcore/pimcoreEPSS 0.62%via GHSA
CVE-2026-6734High· 7.5
3mo ago

undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)

A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.39%via CSAF
CVE-2026-12151High· 7.5
3mo ago

undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)

A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client …

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.79%via CSAF
CVE-2026-9697High· 7.4
3mo ago

undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697)

A flaw was found in undici. When undici's ProxyAgent is configured with a SOCKS5 proxy Uniform Resource Identifier (URI), it silently ignores Transport Layer Security (TLS) options, such as custom Certificate Authorities (CAs). This allows…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.55%via CSAF
CVE-2026-56301Medium· 5.5
3mo ago

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Nuxt dev server vite-node IPC socket is world-connectable on Linux

▾ Sunlitnuxt · nuxtEPSS 0.15%via GHSA
CVEs tagged “ghsa” — page 117 · VulnSea