VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2026-47347Medium
3mo ago

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.48%via GHSA
CVE-2026-47349Medium
3mo ago

TYPO3 CMS has Broken Access Control in the Recycler Module

TYPO3 CMS has Broken Access Control in the Recycler Module

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-11607High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2026-53999High· 7.7
3mo ago

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

▾ Twilightradius-project · github.com/radius-project/radiusvia GHSA
GHSA-g7r4-m6w7-qqqrLow· 2.5
3mo ago

esbuild allows arbitrary file read when running the development server on Windows

esbuild allows arbitrary file read when running the development server on Windows

▾ Sunlitesbuild · esbuildvia GHSA
GHSA-gv7w-rqvm-qjhrHigh· 8.1
3mo ago

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY

▾ Twilightesbuild · esbuildvia GHSA
GHSA-chgr-c6px-7xppMedium
3mo ago

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

▾ Sunlitpyo3 · pyo3via GHSA
CVE-2026-44311Medium· 5.4
3mo ago

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

▾ Sunlitfabric · fabricEPSS 0.27%via GHSA
CVE-2026-54097High
3mo ago

File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix

File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix

▾ Twilightfilebrowser · github.com/filebrowser/filebrowserEPSS 0.45%via GHSA
GHSA-ch3q-cw5r-f4hgMedium
3mo ago

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

▾ Sunlitconnectbot · org.connectbot.sshlib:sshlibvia GHSA
GHSA-vc8p-8pxg-rfwgMedium
3mo ago

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing

▾ Sunlitconnectbot · org.connectbot.sshlib:sshlibvia GHSA
CVE-2026-54096High
3mo ago

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.18%via GHSA
CVE-2026-54092High· 6.5
3mo ago

File Browser has a DoS Vulnerability via Public Login API

File Browser has a DoS Vulnerability via Public Login API

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
CVE-2026-54094Medium· 6.8
3mo ago

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.50%via GHSA
CVE-2026-54093Medium
3mo ago

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.19%via GHSA
CVE-2026-54091High· 7.5
3mo ago

File Browser has incorrect access control for public directory shares via rule path rebasing

File Browser has incorrect access control for public directory shares via rule path rebasing

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.52%via GHSA
CVE-2026-54090High
3mo ago

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.44%via GHSA
CVE-2026-12143High· 7.5PoC
3mo ago

form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…

▾ Midnightform-data · form-dataEPSS 0.67%via CVEORG
CVE-2026-50011High· 7.5PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-50020Medium· 5.3
3mo ago

netty-codec-http: Netty: Data manipulation via request-boundary confusion in HttpObjectDecoder (CVE-2026-50020)

A flaw was found in Netty. The HttpObjectDecoder component, which processes incoming HTTP requests, incorrectly skips certain control characters and whitespace before reading the first request line. This behavior, which goes beyond standar…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.40%via CSAF
CVE-2026-50560Medium· 5.3
3mo ago

netty-codec-http2: Netty: Denial of Service due to HTTP/2 max header size handling (CVE-2026-50560)

A flaw was found in Netty, a network application framework. A remote attacker can exploit a vulnerability in the HTTP/2 (Hypertext Transfer Protocol version 2) maximum header size handling. By sending a specific SETTINGS_MAX_HEADER_LIST_SI…

▾ SunlitRed Hat · OpenShift ServerlessEPSS 0.52%via CSAF
CVE-2026-48059High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…

▾ Twilightnetty · nettyEPSS 0.88%via NVD
CVE-2026-48043Medium· 5.3⚖ disputed
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompre…

▾ Sunlitnetty · nettyEPSS 0.88%via NVD
CVE-2026-47691High· 8.7
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…

▾ Twilightnetty · nettyEPSS 0.36%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

▾ Midnightnetty · nettyEPSS 0.36%via NVD
CVE-2026-44250High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nes…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-44890High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple …

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-49214Medium· 5.3
3mo ago

guzzlehttp/psr7 has CRLF Injection via URI Host Component

guzzlehttp/psr7 has CRLF Injection via URI Host Component

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-48998Medium· 5.3
3mo ago

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-53723Medium· 5.8
3mo ago

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

▾ Sunlitguzzlehttp · guzzlehttp/guzzle-servicesEPSS 0.35%via GHSA
CVEs tagged “ghsa” — page 126 · VulnSea