VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2026-48020HighPoC
3mo ago

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.78%via GHSA
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

▾ Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-48038Medium· 5.3
3mo ago

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

▾ Sunlitjoi · joiEPSS 0.52%via GHSA
CVE-2026-48069High· 7.5
3mo ago

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash

▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48068High· 7.5
3mo ago

@grpc/grpc-js: A malformed request can cause a server crash

@grpc/grpc-js: A malformed request can cause a server crash

▾ Twilightgrpc · @grpc/grpc-jsEPSS 0.88%via GHSA
CVE-2026-48040Medium
3mo ago

netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access

netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringsslEPSS 0.29%via GHSA
CVE-2026-48045Medium· 6.5
3mo ago

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

▾ Sunlitzeroconf · zeroconfEPSS 0.37%via GHSA
CVE-2026-48049Medium· 5.3
3mo ago

@hapi/inert has a static-file confinement bypass via sibling-prefix path

@hapi/inert has a static-file confinement bypass via sibling-prefix path

▾ Sunlithapi · @hapi/inertEPSS 0.59%via GHSA
CVE-2026-48062Critical· 9.8
3mo ago

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

▾ Midnightcodeigniter4 · codeigniter4/frameworkEPSS 0.78%via GHSA
CVE-2026-48067Medium· 6.5
3mo ago

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields

▾ Sunlitfilament · filament/tablesEPSS 0.30%via GHSA
CVE-2026-48089High
3mo ago

DevGuard has improper authorization on public assets

DevGuard has improper authorization on public assets

▾ Twilightl3montree-dev · github.com/l3montree-dev/devguardEPSS 0.36%via GHSA
CVE-2026-48096Medium· 5.0
3mo ago

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.13%via OSV
CVE-2026-48107Medium· 6.5
3mo ago

Russh: Unchecked keyboard-interactive prompt count in client auth path

Russh: Unchecked keyboard-interactive prompt count in client auth path

▾ Sunlitrussh · russhEPSS 0.42%via GHSA
CVE-2026-48108Medium· 5.3
3mo ago

Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input

Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input

▾ Sunlitrussh · russhEPSS 0.47%via GHSA
CVE-2026-11401High· 8.0
3mo ago

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightaws · github.com/aws/aws-advanced-go-wrapper/awssql/v2EPSS 0.30%via GHSA
CVE-2026-48110High· 7.5
3mo ago

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

▾ Twilightrussh · russhEPSS 0.46%via GHSA
CVE-2025-27511High· 7.2
3mo ago

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

▾ Twilightgeoserver · org.geoserver.extension:gs-db2EPSS 1.1%via GHSA
CVE-2026-48109High· 8.2
3mo ago

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

▾ TwilightMessagePack · MessagePackEPSS 0.51%via GHSA
CVE-2025-71330High· 7.5
3mo ago

image-size: ICNS parser allows denial of service through an infinite loop

image-size: ICNS parser allows denial of service through an infinite loop

▾ Twilightimage-size · image-sizeEPSS 0.43%via GHSA
CVE-2025-71329High· 7.5PoC
3mo ago

image-size: JXL and HEIF parsers allow denial of service through infinite loops

image-size: JXL and HEIF parsers allow denial of service through infinite loops

▾ Midnightimage-size · image-sizeEPSS 0.43%via GHSA
CVE-2026-41731High· 8.1
3mo ago

In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

▾ Twilightspringframework · org.springframework.kafka:spring-kafkaEPSS 0.65%via GHSA
CVE-2026-41726Medium· 6.5
3mo ago

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

▾ Sunlitspringframework · org.springframework.kafka:spring-kafkaEPSS 0.42%via GHSA
CVE-2026-47838Medium· 6.8
3mo ago

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates

▾ Sunlitspringframework · org.springframework.security:spring-security-webEPSS 0.19%via GHSA
CVE-2026-48032High
3mo ago

@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers

@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers

▾ Twilighthulumi · @hulumi/policiesEPSS 0.54%via GHSA
CVE-2026-48033High
3mo ago

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

▾ Twilighthulumi · @hulumi/policiesEPSS 0.48%via GHSA
CVE-2026-48034High
3mo ago

@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

▾ Twilighthulumi · @hulumi/policiesEPSS 0.45%via GHSA
CVE-2026-48035High
3mo ago

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

▾ Twilighthulumi · @hulumi/baselineEPSS 0.45%via GHSA
CVE-2026-48036High
3mo ago

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

▾ Twilighthulumi · @hulumi/driftEPSS 0.51%via GHSA
CVE-2026-48037Medium
3mo ago

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

▾ Sunlithulumi · @hulumi/baselineEPSS 0.45%via GHSA
CVE-2026-48051Low· 3.5
3mo ago

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

Papra HTTP redirect bypass can lead to SSRF via webhook delivery system

▾ Sunlitpapra · @papra/webhooksEPSS 0.26%via GHSA
CVEs tagged “ghsa” — page 127 · VulnSea