Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2026-49396High· 7.1Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
CVE-2026-49397Medium· 5.3Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
CVE-2025-53114High· 7.5Acknowledgement extension out of memory
Acknowledgement extension out of memory
CVE-2026-48025Mediumnebula-mesh: Decrypted CA private key persists in heap after signing
nebula-mesh: Decrypted CA private key persists in heap after signing
CVE-2026-48058Mediumnebula-mesh: Session and OIDC state cookies lack the Secure attribute
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-48060High· 8.1PoCLitestar has HTML Injection Through its CSRF Token
Litestar has HTML Injection Through its CSRF Token
CVE-2026-47751MediumClaude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
CVE-2026-47768Medium· 5.5nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
CVE-2026-52726Medium· 5.4⚖ disputeddulwich: Dulwich: Arbitrary code execution via crafted Git submodules (CVE-2026-52726)
A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updat…
CVE-2026-40984High· 7.5In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.1…
CVE-2026-47737High· 7.5Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
CVE-2026-47240MediumNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-47241LowNet::IMAP: Denial of Service via incomplete raw argument validation
Net::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-47242MediumNet::IMAP: Command Injection via ID command argument
Net::IMAP: Command Injection via ID command argument
CVE-2026-47767MediumSymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
CVE-2026-8467CriticalPoCPhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
CVE-2026-8469HighPhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
CVE-2026-47068LowPhoenixStorybook has cross-session PubSub topic injection via URL parameter
PhoenixStorybook has cross-session PubSub topic injection via URL parameter
GHSA-7qjx-gp9h-65qjHigh· 8.7Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
CVE-2026-48030Critical· 9.9PoCPheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
CVE-2026-45591High· 7.5ASP.NET Core Denial of Service Vulnerability
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-45491Medium· 6.2.NET Tampering Vulnerability
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
CVE-2026-40983High· 7.5In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
CVE-2026-41855High· 8.1In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to u…
CVE-2026-47430CriticalCordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
CVE-2026-39922Medium· 6.3GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
CVE-2026-49233HighRoutinator has cache path traversal when processing the module component of rsync URIs
Routinator has cache path traversal when processing the module component of rsync URIs
CVE-2026-49235HighRoutinator crashes when encountering maliciously crafted RRDP XML files
Routinator crashes when encountering maliciously crafted RRDP XML files
CVE-2026-49234High· 7.5Routinator crashes when sending a maliciously crafted select-asn query parameter
Routinator crashes when sending a maliciously crafted select-asn query parameter
CVE-2026-41479Medium· 5.4Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type