VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3916 CVEsRSS

CVE-2026-42890Medium
3mo ago

actual Allows Electron to Run As Node

actual Allows Electron to Run As Node

▾ Sunlitactual · actualEPSS 0.18%via GHSA
CVE-2026-44892High· 7.5
3mo ago

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.49%via GHSA
CVE-2026-44894High· 7.5
3mo ago

Netty's Default QUIC token handler accepts any client-supplied token

Netty's Default QUIC token handler accepts any client-supplied token

▾ Twilightnetty · io.netty:netty-codec-classes-quicEPSS 0.19%via GHSA
CVE-2026-45034CriticalPoC
3mo ago

PHPSpreadsheet has a patch bypass for CVE-2026-34084

PHPSpreadsheet has a patch bypass for CVE-2026-34084

▾ Abyssalphpoffice · phpoffice/phpspreadsheetEPSS 0.46%via GHSA
CVE-2026-47693Medium· 6.9
3mo ago

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

▾ Sunlitpoweradmin · poweradmin/poweradminEPSS 0.38%via GHSA
CVE-2026-47712Low· 3.3
3mo ago

Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`

Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`

▾ Sunlitdulwich · dulwichEPSS 0.18%via GHSA
CVE-2026-47722High
3mo ago

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.47%via GHSA
CVE-2026-47723High
3mo ago

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.53%via GHSA
CVE-2026-47724Critical· 9.9
3mo ago

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

▾ Midnightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
CVE-2026-47725High
3mo ago

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.22%via GHSA
CVE-2026-47726High
3mo ago

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.41%via GHSA
CVE-2026-47734Medium· 5.7
3mo ago

Dulwich has unbounded memory allocation in receive-pack from crafted thin packs

Dulwich has unbounded memory allocation in receive-pack from crafted thin packs

▾ Sunlitdulwich · dulwichEPSS 0.33%via GHSA
CVE-2026-47736High· 7.5
3mo ago

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

▾ Twilightpuma · pumaEPSS 0.63%via GHSA
CVE-2026-33244Medium· 5.4
3mo ago

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

▾ Sunlitreact-router · react-routerEPSS 0.14%via GHSA
CVE-2026-48596Low· 3.7PoC
4mo ago

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_typ…

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_typ…

▾ Twilightelixir-tesla · teslaEPSS 0.35%via NVD
CVE-2026-48594High· 7.5
4mo ago

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware…

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware…

▾ Twilightelixir-tesla · teslaEPSS 0.70%via NVD
CVE-2026-48595Medium· 5.9PoC⚖ disputed
4mo ago

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…

▾ Twilightelixir-tesla · teslaEPSS 0.67%via NVD
CVE-2026-48597Medium· 5.9PoC⚖ disputed
4mo ago

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …

▾ Twilightelixir-tesla · teslaEPSS 0.63%via NVD
CVE-2026-48598Low· 3.7PoC
4mo ago

Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disp…

Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disp…

▾ Twilightelixir-tesla · teslaEPSS 0.34%via NVD
CVE-2026-35630High· 8.0
4mo ago

OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval Buttons

OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval buttons to resolve pending exec or plugin…

▾ TwilightOpenClaw · OpenClawEPSS 0.36%via CVEORG
CVE-2026-48523Medium· 5.4
4mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked agains…

▾ Sunlitpyjwt_project · pyjwtEPSS 0.17%via NVD
CVE-2026-46598Medium· 5.3
4mo ago

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

▾ Sunlitx · golang.org/x/cryptoEPSS 0.52%via OSV
CVE-2026-39833Medium· 5.5⚖ disputed
4mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation (CVE-2026-39833)

A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before u…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-39832Critical· 9.1
4mo ago

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of…

▾ Midnightgolang · cryptoEPSS 0.72%via NVD
CVE-2026-46597High· 7.5
4mo ago

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

▾ Twilightx · golang.org/x/cryptoEPSS 0.62%via OSV
CVE-2026-39828Medium· 6.3⚖ disputed
4mo ago

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succee…

▾ Sunlitgolang.org/x/crypto · golang.org/x/crypto/sshEPSS 0.54%via CVEORG
CVE-2026-39835Medium· 5.3
4mo ago

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these…

▾ Sunlitgolang · cryptoEPSS 0.66%via NVD
CVE-2026-39827Medium· 6.5
4mo ago

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh

▾ Sunlitx · golang.org/x/cryptoEPSS 0.28%via OSV
CVE-2026-39830Critical· 9.1
4mo ago

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connec…

▾ Midnightgolang · cryptoEPSS 0.62%via NVD
CVE-2026-39829High· 7.5
4mo ago

The RSA and DSA public key parsers did not enforce size limits on key parameters

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This …

▾ Twilightgolang · cryptoEPSS 0.62%via NVD
CVEs tagged “ghsa” — page 129 · VulnSea