VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3917 CVEsRSS

CVE-2026-49396High· 7.1
3mo ago

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.17%via GHSA
CVE-2026-49397Medium· 5.3
3mo ago

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.34%via GHSA
CVE-2025-53114High· 7.5
3mo ago

Acknowledgement extension out of memory

Acknowledgement extension out of memory

▾ Twilightcometd · org.cometd.java:cometd-java-server-commonEPSS 0.68%via GHSA
CVE-2026-48025Medium
3mo ago

nebula-mesh: Decrypted CA private key persists in heap after signing

nebula-mesh: Decrypted CA private key persists in heap after signing

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.51%via GHSA
CVE-2026-48058Medium
3mo ago

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.32%via GHSA
CVE-2026-48060High· 8.1PoC
3mo ago

Litestar has HTML Injection Through its CSRF Token

Litestar has HTML Injection Through its CSRF Token

▾ Midnightlitestar · litestarEPSS 0.40%via GHSA
CVE-2026-47751Medium
3mo ago

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

▾ Sunlitanthropics · anthropics/claude-code-actionEPSS 0.77%via GHSA
CVE-2026-47768Medium· 5.5
3mo ago

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.15%via GHSA
CVE-2026-52726Medium· 5.4⚖ disputed
3mo ago

dulwich: Dulwich: Arbitrary code execution via crafted Git submodules (CVE-2026-52726)

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updat…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.68%via CSAF
CVE-2026-40984High· 7.5
3mo ago

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…

▾ TwilightSpring · micrometer-coreEPSS 1.1%via NVD
CVE-2026-47737High· 7.5
3mo ago

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

▾ Twilightpuma · pumaEPSS 0.27%via GHSA
CVE-2026-47240Medium
3mo ago

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument

▾ Sunlitnet-imap · net-imapEPSS 0.83%via GHSA
CVE-2026-47241Low
3mo ago

Net::IMAP: Denial of Service via incomplete raw argument validation

Net::IMAP: Denial of Service via incomplete raw argument validation

▾ Sunlitnet-imap · net-imapEPSS 0.38%via GHSA
CVE-2026-47242Medium
3mo ago

Net::IMAP: Command Injection via ID command argument

Net::IMAP: Command Injection via ID command argument

▾ Sunlitnet-imap · net-imapEPSS 0.18%via GHSA
CVE-2026-47767Medium
3mo ago

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

▾ Sunlitsymfony · symfony/runtimeEPSS 0.72%via GHSA
CVE-2026-8467CriticalPoC
3mo ago

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

▾ Abyssalphoenix_storybook · phoenix_storybookEPSS 2.1%via GHSA
CVE-2026-8469High
3mo ago

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

▾ Twilightphoenix_storybook · phoenix_storybookEPSS 0.52%via GHSA
CVE-2026-47068Low
3mo ago

PhoenixStorybook has cross-session PubSub topic injection via URL parameter

PhoenixStorybook has cross-session PubSub topic injection via URL parameter

▾ Sunlitphoenix_storybook · phoenix_storybookEPSS 0.53%via GHSA
GHSA-7qjx-gp9h-65qjHigh· 8.7
3mo ago

Dex: Token-exchange endpoint is missing AllowedConnectors enforcement

Dex: Token-exchange endpoint is missing AllowedConnectors enforcement

▾ Twilightdexidp · github.com/dexidp/dexvia GHSA
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

▾ Abyssalpheditor · pheditor/pheditorEPSS 7.5%via GHSA
CVE-2026-45591High· 7.5
3mo ago

ASP.NET Core Denial of Service Vulnerability

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 2.4%via CVEORG
CVE-2026-45491Medium· 6.2
3mo ago

.NET Tampering Vulnerability

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.37%via CVEORG
CVE-2026-40983High· 7.5
3mo ago

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

▾ TwilightSpring · MicrometerEPSS 0.85%via NVD
CVE-2026-41855High· 8.1
3mo ago

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…

▾ Twilightspringframework · org.springframework:spring-jmsEPSS 0.48%via NVD
CVE-2026-47430Critical
3mo ago

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

▾ Midnightcordova-plugin-inappbrowser · cordova-plugin-inappbrowserEPSS 0.77%via GHSA
CVE-2026-39922Medium· 6.3
3mo ago

GeoNode contains a server-side request forgery vulnerability in the service registration endpoint

GeoNode contains a server-side request forgery vulnerability in the service registration endpoint

▾ Sunlitgeonode · geonodeEPSS 0.27%via GHSA
CVE-2026-49233High
3mo ago

Routinator has cache path traversal when processing the module component of rsync URIs

Routinator has cache path traversal when processing the module component of rsync URIs

▾ Twilightroutinator · routinatorEPSS 0.50%via GHSA
CVE-2026-49235High
3mo ago

Routinator crashes when encountering maliciously crafted RRDP XML files

Routinator crashes when encountering maliciously crafted RRDP XML files

▾ Twilightroutinator · routinatorEPSS 0.46%via GHSA
CVE-2026-49234High· 7.5
3mo ago

Routinator crashes when sending a maliciously crafted select-asn query parameter

Routinator crashes when sending a maliciously crafted select-asn query parameter

▾ Twilightroutinator · routinatorEPSS 0.33%via GHSA
CVE-2026-41479Medium· 5.4
3mo ago

Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type

Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type

▾ Sunlitauthlib · authlibEPSS 0.26%via GHSA
CVEs tagged “ghsa” — page 128 · VulnSea