Tagged “ghsa”
CVEs tagged ghsa, newest first.
3916 CVEsRSS
GHSA-m557-wrgg-6rp4Medium· 5.8phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access
phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access
CVE-2026-12398High· 7.5Galaxy NG: command injection vulnerability
Galaxy NG: command injection vulnerability
CVE-2026-33760High· 8.8Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVE-2026-42867Medium· 6.5Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-48519Critical· 9.6PoCLangflow: Unauthenticated RCE in Shareable Playgrounds
Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-48520Medium· 6.1Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-49444High· 8.5n8n: Python sandbox escape
n8n: Python sandbox escape
CVE-2026-49465Medium· 7.7n8n: Git Node Clone and Push Operations Bypass File Sandbox
n8n: Git Node Clone and Push Operations Bypass File Sandbox
CVE-2026-54310Medium· 9.9n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes
CVE-2026-54313Medium· 7.7n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
n8n: NoSQL Injection in MongoDB Node Find And Replace Operation
GHSA-hv7x-3x78-gx53Medium· 7.4n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-54308Medium· 7.2n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
CVE-2026-54301High· 7.6n8n: Same-Origin XSS in Respond to Webhook Node
n8n: Same-Origin XSS in Respond to Webhook Node
CVE-2026-54306Medium· 5.4n8n: Prototype Pollution enables confused-deputy execution via public webhooks
n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54311Medium· 6.3n8n: Merge Node SQL Mode Prototype Pollution
n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-48491HighTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
CVE-2026-49859Medium· 5.2Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVE-2026-49860Medium· 5.2Deno: WebSocket API sandbox bypass via missing post-DNS check
Deno: WebSocket API sandbox bypass via missing post-DNS check
CVE-2026-49402High· 8.1Deno: Command Injection via spawnSync & spawn on Windows
Deno: Command Injection via spawnSync & spawn on Windows
CVE-2026-49440High· 7.4Deno: Miller-Rabin Primality Test Allows Zero Rounds
Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-49411Medium· 6.5Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
CVE-2026-49406Medium· 5.5Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
CVE-2026-49401Medium· 5.2Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
CVE-2026-50133MediumHugo: XSS via text/html content files
Hugo: XSS via text/html content files
CVE-2026-50134MediumHugo: security.http.urls allow-list bypass via HTTP redirects
Hugo: security.http.urls allow-list bypass via HTTP redirects
CVE-2026-50135MediumHugo: Symlink confinement bypass in resources.Get
Hugo: Symlink confinement bypass in resources.Get
CVE-2026-53753Critical· 9.8PoCCrawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-56266Critical· 9.8Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
CVE-2026-54157Critical· 9.0PoCLobeHub: Unauthenticated SSRF in `/webapi/proxy`
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
CVE-2026-50019Medium· 6.1yt-dlp: File Downloader cookie leak with curl
yt-dlp: File Downloader cookie leak with curl