Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2026-56317LowCross-site scripting via <NoScript> slot content in Nuxt's head components
Cross-site scripting via <NoScript> slot content in Nuxt's head components
CVE-2026-48735Mediumpypdf: Manipulated XMP metadata streams can exhaust RAM
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-49460Mediumpypdf: Inefficient decoding of FlateDecode PNG predictor streams
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVE-2026-49461Mediumpypdf: Possible large memory usage for form XObjects during text extraction
pypdf: Possible large memory usage for form XObjects during text extraction
CVE-2026-56326Medium· 6.1Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
CVE-2026-53721HighNuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
GHSA-534h-c3cw-v3h9Medium· 5.5Nuxt dev server vite-node IPC socket is world-connectable on Linux
Nuxt dev server vite-node IPC socket is world-connectable on Linux
CVE-2026-53722MediumNuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
CVE-2026-50146High· 7.1Astro: Reflected XSS via unescaped slot name
Astro: Reflected XSS via unescaped slot name
CVE-2026-54530Mediumpypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-54531Mediumpypdf: Possible infinite loop when processing outlines/bookmarks in writer
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
GHSA-8rfp-98v4-mmr6Low· 0.0Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
GHSA-g75f-g53v-794xMedium· 4.3Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
GHSA-gj48-438w-jh9vMedium· 6.1Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
CVE-2026-54287Medium· 5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-54286Medium· 5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54290High· 7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVE-2026-54289Medium· 4.8hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
CVE-2026-54288Medium· 6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
CVE-2026-54300Medium· 5.3@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
CVE-2026-54299High· 7.5Astro: Host header SSRF in prerendered error page fetch
Astro: Host header SSRF in prerendered error page fetch
CVE-2026-54298Medium· 4.2Astro: XSS via Unescaped Attribute Names in Spread Props
Astro: XSS via Unescaped Attribute Names in Spread Props
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
GHSA-m557-wrgg-6rp4Medium· 5.8phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access
phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access
CVE-2026-12398High· 7.5Galaxy NG: command injection vulnerability
Galaxy NG: command injection vulnerability
CVE-2026-33760High· 8.8Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVE-2026-42867Medium· 6.5Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-48519Critical· 9.6PoCLangflow: Unauthenticated RCE in Shareable Playgrounds
Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-48520Medium· 6.1Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-49444High· 8.5n8n: Python sandbox escape
n8n: Python sandbox escape