VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2026-56317Low
3mo ago

Cross-site scripting via <NoScript> slot content in Nuxt's head components

Cross-site scripting via <NoScript> slot content in Nuxt's head components

▾ Sunlitnuxt · nuxtEPSS 0.34%via GHSA
CVE-2026-48735Medium
3mo ago

pypdf: Manipulated XMP metadata streams can exhaust RAM

pypdf: Manipulated XMP metadata streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.18%via GHSA
CVE-2026-49460Medium
3mo ago

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

▾ Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-49461Medium
3mo ago

pypdf: Possible large memory usage for form XObjects during text extraction

pypdf: Possible large memory usage for form XObjects during text extraction

▾ Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-56326Medium· 6.1
3mo ago

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`

▾ Sunlitnuxt · nuxtEPSS 0.36%via GHSA
CVE-2026-53721High
3mo ago

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

▾ Twilightnuxt · nuxtEPSS 0.51%via GHSA
GHSA-534h-c3cw-v3h9Medium· 5.5
3mo ago

Nuxt dev server vite-node IPC socket is world-connectable on Linux

Nuxt dev server vite-node IPC socket is world-connectable on Linux

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-53722Medium
3mo ago

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL

▾ Sunlitnuxt · nuxtEPSS 0.33%via GHSA
CVE-2026-50146High· 7.1
3mo ago

Astro: Reflected XSS via unescaped slot name

Astro: Reflected XSS via unescaped slot name

▾ Twilightastro · astroEPSS 0.27%via GHSA
CVE-2026-54530Medium
3mo ago

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-54531Medium
3mo ago

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
GHSA-8rfp-98v4-mmr6Low· 0.0
3mo ago

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

▾ Sunlitbleach · bleachvia OSV
GHSA-g75f-g53v-794xMedium· 4.3
3mo ago

Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning

Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning

▾ Sunlitbleach · bleachvia GHSA
GHSA-gj48-438w-jh9vMedium· 6.1
3mo ago

Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes

Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes

▾ Sunlitbleach · bleachvia OSV
CVE-2026-54287Medium· 5.3
3mo ago

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

▾ Sunlithono · honoEPSS 0.31%via GHSA
CVE-2026-54286Medium· 5.9
3mo ago

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

▾ Sunlithono · honoEPSS 0.43%via GHSA
CVE-2026-54290High· 7.1
3mo ago

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

▾ Twilighthono · honoEPSS 0.33%via GHSA
CVE-2026-54289Medium· 4.8
3mo ago

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

▾ Sunlithono · honoEPSS 0.18%via GHSA
CVE-2026-54288Medium· 6.5
3mo ago

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

▾ Sunlithono · honoEPSS 0.15%via GHSA
CVE-2026-54300Medium· 5.3
3mo ago

@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config

@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config

▾ Sunlitastrojs · @astrojs/netlifyEPSS 0.31%via GHSA
CVE-2026-54299High· 7.5
3mo ago

Astro: Host header SSRF in prerendered error page fetch

Astro: Host header SSRF in prerendered error page fetch

▾ Twilightastro · astroEPSS 0.33%via GHSA
CVE-2026-54298Medium· 4.2
3mo ago

Astro: XSS via Unescaped Attribute Names in Spread Props

Astro: XSS via Unescaped Attribute Names in Spread Props

▾ Sunlitastro · astroEPSS 0.23%via GHSA
GHSA-gr75-jv2w-4656Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

▾ Sunlitlangchain · langchainvia GHSA
GHSA-m557-wrgg-6rp4Medium· 5.8
3mo ago

phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access

phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access

▾ Sunlitphpseclib · phpseclib/phpseclibvia GHSA
CVE-2026-12398High· 7.5
3mo ago

Galaxy NG: command injection vulnerability

Galaxy NG: command injection vulnerability

▾ Twilightgalaxy-ng · galaxy-ngEPSS 0.89%via GHSA
CVE-2026-33760High· 8.8
3mo ago

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

▾ Twilightlangflow · langflowEPSS 0.50%via GHSA
CVE-2026-42867Medium· 6.5
3mo ago

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.47%via GHSA
CVE-2026-48519Critical· 9.6PoC
3mo ago

Langflow: Unauthenticated RCE in Shareable Playgrounds

Langflow: Unauthenticated RCE in Shareable Playgrounds

▾ Abyssallangflow · langflowEPSS 0.78%via GHSA
CVE-2026-48520Medium· 6.1
3mo ago

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

▾ Sunlitlangflow · langflowEPSS 0.44%via GHSA
CVE-2026-49444High· 8.5
3mo ago

n8n: Python sandbox escape

n8n: Python sandbox escape

▾ Twilightn8n · n8nEPSS 0.39%via GHSA
CVEs tagged “ghsa” — page 118 · VulnSea