Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2026-27783Medium· 4.3Gitea: Missing repository-unit authorization on issue-template API endpoints
Gitea: Missing repository-unit authorization on issue-template API endpoints
CVE-2026-20706MediumGitea: Token scope bypass on web archive download endpoint
Gitea: Token scope bypass on web archive download endpoint
CVE-2026-54326Low· 2.5Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
CVE-2026-12208Medium· 5.3jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
CVE-2026-48853Critical· 9.2PoCDeserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flow…
CVE-2026-48599High· 7.6PoCAuthorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…
Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting value for any path-bound field via the qu…
CVE-2026-48854High· 8.7PoCAllocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…
Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming a large or slow-trickle unary request body. 'Elixir.G…
CVE-2026-54267HighAngular Client Hydration DOM Clobbering & Response-Cache Poisoning
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
CVE-2026-49982High· 8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
CVE-2026-50168High@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
CVE-2026-50169MediumAngular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
CVE-2026-48761MediumSymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes
CVE-2026-52725Medium@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
CVE-2026-50170High@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
CVE-2026-50171High@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVE-2026-50184Medium@angular/service-worker: Request Credential & Cache Policy Stripping
@angular/service-worker: Request Credential & Cache Policy Stripping
CVE-2026-49356Low· 3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
@babel/core: Arbitrary File Read via sourceMappingURL Comment
CVE-2026-53571HighPoCvite: `server.fs.deny` bypass on Windows alternate paths
vite: `server.fs.deny` bypass on Windows alternate paths
CVE-2026-53632Mediumlaunch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2026-53655Mediumnode-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
CVE-2026-50555High@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-50557MediumAngular: Template and Attribute Namespace Sanitization Bypass (XSS)
Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
CVE-2026-54265Medium@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
CVE-2026-54266High@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
CVE-2026-54268High@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
CVE-2026-54264High@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
CVE-2026-54269Medium· 5.3protobufjs : Schema-derived names can shadow runtime-significant properties
protobufjs : Schema-derived names can shadow runtime-significant properties
CVE-2026-48489HighSymfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
CVE-2026-48524Low· 3.7PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVE-2026-48712High· 7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
protobufjs: Denial of service through unbounded Any expansion during JSON conversion