Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2026-48020HighPoCTraefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
CVE-2026-48022Medium· 6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVE-2026-48038Medium· 5.3joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
CVE-2026-48069High· 7.5@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-48068High· 7.5@grpc/grpc-js: A malformed request can cause a server crash
@grpc/grpc-js: A malformed request can cause a server crash
CVE-2026-48040Mediumnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVE-2026-48045Medium· 6.5python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
CVE-2026-48049Medium· 5.3@hapi/inert has a static-file confinement bypass via sibling-prefix path
@hapi/inert has a static-file confinement bypass via sibling-prefix path
CVE-2026-48062Critical· 9.8CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
CVE-2026-48067Medium· 6.5Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
CVE-2026-48089HighDevGuard has improper authorization on public assets
DevGuard has improper authorization on public assets
CVE-2026-48096Medium· 5.0OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
CVE-2026-48107Medium· 6.5Russh: Unchecked keyboard-interactive prompt count in client auth path
Russh: Unchecked keyboard-interactive prompt count in client auth path
CVE-2026-48108Medium· 5.3Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
CVE-2026-11401High· 8.0AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-48110High· 7.5Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
CVE-2025-27511High· 7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVE-2026-48109High· 8.2MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
CVE-2025-71330High· 7.5image-size: ICNS parser allows denial of service through an infinite loop
image-size: ICNS parser allows denial of service through an infinite loop
CVE-2025-71329High· 7.5PoCimage-size: JXL and HEIF parsers allow denial of service through infinite loops
image-size: JXL and HEIF parsers allow denial of service through infinite loops
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-41726Medium· 6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVE-2026-47838Medium· 6.8Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
CVE-2026-48032High@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
CVE-2026-48033High@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
CVE-2026-48034High@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
CVE-2026-48035High@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
CVE-2026-48036High@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
CVE-2026-48037Medium@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
CVE-2026-48051Low· 3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system