VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3916 CVEsRSS

CVE-2026-54257Critical
3mo ago

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow

▾ Midnightelectron · electronEPSS 0.43%via GHSA
CVE-2026-53537Low· 3.7
3mo ago

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

▾ Sunlitpython-multipart · python-multipartEPSS 0.29%via OSV
CVE-2026-53538Low· 3.7
3mo ago

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

▾ Sunlitpython-multipart · python-multipartEPSS 0.26%via OSV
CVE-2026-53540Low· 3.7
3mo ago

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

▾ Sunlitpython-multipart · python-multipartEPSS 0.34%via OSV
CVE-2026-53539High· 7.5
3mo ago

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

▾ Twilightpython-multipart · python-multipartEPSS 0.46%via OSV
CVE-2026-54281High
3mo ago

Nest: Middleware Bypass on Fastify via Trailing Slash

Nest: Middleware Bypass on Fastify via Trailing Slash

▾ Twilightnestjs · @nestjs/platform-fastifyEPSS 0.50%via GHSA
GHSA-pw6j-qg29-8w7fMedium· 5.9
3mo ago

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

▾ Sunlittornado · tornadovia OSV
CVE-2026-54282Low· 3.7
3mo ago

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

▾ Sunlitstarlette · starletteEPSS 0.27%via OSV
CVE-2026-54285Medium· 5.3
3mo ago

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation

▾ Sunlitopentelemetry · @opentelemetry/coreEPSS 0.40%via GHSA
CVE-2026-48988Medium· 5.3
3mo ago

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

▾ Sunlitmarkdown-it · markdown-itEPSS 0.43%via GHSA
CVE-2026-48748High· 7.5
3mo ago

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.68%via GHSA
CVE-2026-50009Medium· 4.8
3mo ago

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

▾ Sunlitnetty · io.netty:netty-codec-classes-quicEPSS 0.32%via GHSA
CVE-2026-11417High· 7.3PoC
3mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Bundling

▾ Midnightaws-cdk-lib · aws-cdk-libEPSS 0.99%via GHSA
GHSA-rq7w-g337-39qqLow
3mo ago

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-30120Critical· 9.8
3mo ago

Remotion: remote code execution (RCE) vulnerability

Remotion: remote code execution (RCE) vulnerability

▾ Midnightremotion · remotionEPSS 0.87%via GHSA
CVE-2026-30121Critical· 9.1
3mo ago

Remotion: arbitrary file write vulnerability

Remotion: arbitrary file write vulnerability

▾ Midnightremotion · remotionEPSS 0.48%via GHSA
CVE-2026-5038High· 7.5⚖ disputed
3mo ago

multer: Multer: Denial of Service via aborted or malformed multipart uploads (CVE-2026-5038)

A flaw was found in multer. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by initiating and then aborting or sending malformed multipart uploads. This action leaves orphaned partial files on the disk, whi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
CVE-2026-5079High· 7.5
3mo ago

multer: Multer: Denial of Service via deeply nested field names in multipart form data (CVE-2026-5079)

A flaw was found in Multer. A remote attacker can exploit this vulnerability by sending a single HTTP request with crafted multipart form data containing deeply nested field names. This can force the allocation of deeply nested object stru…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.49%via CSAF
GHSA-v82c-5c2q-hx9gMedium
3mo ago

Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

▾ Sunlitgrafana · github.com/grafana/grafana-operatorvia GHSA
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
CVE-2026-45536Medium· 4.0
3mo ago

netty-transport-native-epoll: netty-transport-native-kqueue: Netty: Denial of Service due to file descriptor leak in SCM_RIGHTS message han…

A flaw was found in Netty, a network application framework. A local attacker could exploit a vulnerability in the `netty_unix_socket_recvFd` function when handling `SCM_RIGHTS` messages in `Epoll` or `KQueue DomainSocketChannel` with `Doma…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.19%via CSAF
CVE-2026-45673Medium· 6.8
3mo ago

netty-resolver-dns: Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs (CVE-2026-45673)

A flaw was found in Netty's DNS resolver component. This vulnerability arises from the use of a predictable pseudo-random number generator (PRNG) for DNS transaction IDs and a static User Datagram Protocol (UDP) source port. This combinati…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.40%via CSAF
CVE-2026-46340High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-47244Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service via uncontrolled HTTP/2 concurrent streams (CVE-2026-47244)

A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a large number of HTTP/2 stream requests to a Netty HTTP/2 server. If the server does not explicitly limit concurrent s…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.51%via CSAF
CVE-2026-48006High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipe…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
GHSA-9r4w-jg96-92mvMedium· 6.8
3mo ago

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

▾ Sunlitgoogle · github.com/google/go-attestationvia GHSA
GHSA-6jq6-x4cx-qvcmMedium
3mo ago

Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)

Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)

▾ Sunlitgrumpydictator · grumpydictator/firefly-iiivia GHSA
CVE-2026-28970Medium
3mo ago

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

▾ Sunlitapple · github.com/apple/swift-niovia GHSA
CVE-2026-43671High
3mo ago

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

▾ Twilightapple · github.com/apple/swift-niovia GHSA
CVE-2026-28980High
3mo ago

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

▾ Twilightapple · github.com/apple/swift-niovia GHSA
CVEs tagged “ghsa” — page 124 · VulnSea