VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2026-48736Medium
3mo ago

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

▾ Sunlitsymfony · symfony/http-clientEPSS 0.57%via GHSA
CVE-2026-48747Medium
3mo ago

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

▾ Sunlitsymfony · symfony/mailomat-mailerEPSS 0.25%via GHSA
CVE-2026-48760Medium
3mo ago

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

▾ Sunlitsymfony · symfony/html-sanitizerEPSS 0.34%via GHSA
CVE-2026-48784Medium
3mo ago

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

▾ Sunlitsymfony · symfony/routingEPSS 0.35%via GHSA
GHSA-r7g4-qg5f-qqm2Medium· 6.5
3mo ago

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

Nodemailer: Improper TLS Certificate Validation in OAuth2 Token Fetch Enables Credential Interception

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-wqvq-jvpq-h66fMedium· 5.4
3mo ago

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

▾ Sunlitnodemailer · nodemailervia GHSA
GHSA-268h-hp4c-crq3Medium· 5.4
3mo ago

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary message header injection

▾ Sunlitnodemailer · nodemailervia GHSA
CVE-2026-48522Medium· 4.2
3mo ago

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

▾ Sunlitpyjwt · pyjwtEPSS 0.22%via OSV
CVE-2026-48525Medium· 5.3
3mo ago

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

▾ Sunlitpyjwt · pyjwtEPSS 0.41%via OSV
CVE-2026-49459Medium· 6.1
3mo ago

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

▾ Sunlitdompurify · dompurifyEPSS 0.36%via GHSA
CVE-2026-49458Medium· 6.1
3mo ago

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

▾ Sunlitdompurify · dompurifyEPSS 0.40%via GHSA
GHSA-76mc-f452-cxcmMedium· 6.1
3mo ago

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-x4vx-rjvf-j5p4Low
3mo ago

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-gvmj-g25r-r7wrLow
3mo ago

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-53633Critical· 9.8
3mo ago

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

▾ Midnightvitest · @vitest/browserEPSS 0.90%via GHSA
CVE-2026-53663Low· 3.1
3mo ago

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

▾ Sunlitreact-router · react-routerEPSS 0.15%via GHSA
CVE-2026-50269Low
3mo ago

aiohttp: CRLF injection in multipart headers

aiohttp: CRLF injection in multipart headers

▾ Sunlitaiohttp · aiohttpEPSS 0.53%via OSV
CVE-2026-54279Low
3mo ago

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54277Medium
3mo ago

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines

▾ Sunlitaiohttp · aiohttpEPSS 0.56%via OSV
CVE-2026-54278Medium
3mo ago

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54273Medium
3mo ago

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

aiohttp: HTTP/1 Pipelined Requests Queue Without Limit

▾ Sunlitaiohttp · aiohttpEPSS 0.49%via OSV
CVE-2026-54275Low
3mo ago

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

▾ Sunlitaiohttp · aiohttpEPSS 0.47%via OSV
CVE-2026-54274Medium
3mo ago

aiohttp: Incomplete websocket frame payloads bypass memory limits

aiohttp: Incomplete websocket frame payloads bypass memory limits

▾ Sunlitaiohttp · aiohttpEPSS 0.54%via OSV
GHSA-537c-gmf6-5ccfHigh· 7.5
3mo ago

Vulnerable OpenSSL included in cryptography wheels

Vulnerable OpenSSL included in cryptography wheels

▾ Twilightcryptography · cryptographyvia OSV
GHSA-vxr8-fq34-vvx9Low
3mo ago

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-54270Medium· 5.3
3mo ago

protobufjs: Memory amplification from preserved unknown fields in binary decode

protobufjs: Memory amplification from preserved unknown fields in binary decode

▾ Sunlitprotobufjs · protobufjsEPSS 0.40%via GHSA
CVE-2026-54271High· 8.2
3mo ago

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

▾ Twilightprotobufjs-cli · protobufjs-cliEPSS 0.30%via GHSA
CVE-2026-48125Medium· 5.3
3mo ago

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

▾ Sunlitua-parser-js · ua-parser-jsEPSS 0.52%via GHSA
CVE-2026-48817Medium· 5.3
3mo ago

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

▾ Sunlitstarlette · starletteEPSS 0.35%via OSV
CVE-2026-48818High· 7.5
3mo ago

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

▾ Twilightstarlette · starletteEPSS 0.65%via OSV
CVEs tagged “ghsa” — page 123 · VulnSea