VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3811 CVEsRSS

CVE-2026-59157Medium· 6.5
1w ago

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…

▾ Sunlitncarlier · webhookdEPSS 0.60%via NVD
CVE-2026-55864High· 7.8
1w ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validati…

▾ Twilightgeonetwork · core-geonetworkEPSS 0.59%via NVD
CVE-2026-50024Medium· 5.3
1w ago

GitHacker is a tool that restores Git repositories from exposed .git directories

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs…

▾ SunlitWangYihang · GitHackerEPSS 0.45%via NVD
CVE-2026-44282Medium· 4.8
1w ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_titl…

▾ Sunlitdecidim · decidimEPSS 0.39%via NVD
CVE-2026-54050Medium· 6.5PoC
1w ago

Sakai is a Collaboration and Learning Environment (CLE)

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.r…

▾ Twilightsakaiproject · sakaiEPSS 0.31%via NVD
CVE-2026-54167High· 8.2
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…

▾ Twilighttektoncd · pipelines-as-codeEPSS 0.27%via NVD
CVE-2026-54168Medium· 6.5
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …

▾ Sunlittektoncd · pipelines-as-codeEPSS 0.59%via NVD
CVE-2026-54251High· 8.7
1w ago

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…

▾ Twilightnetty · netty-incubator-codec-ohttpEPSS 0.51%via NVD
CVE-2026-55149High· 7.5PoC
1w ago

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the val…

▾ Midnightvouch · vouch-proxyEPSS 0.72%via NVD
CVE-2026-53941Medium· 6.9
1w ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to co…

▾ Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.52%via NVD
CVE-2026-53957High· 7.7PoC
1w ago

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-…

▾ Midnightcontentful · contentful-mcp-serverEPSS 0.41%via NVD
CVE-2026-53966High· 7.1
1w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document…

▾ Twilightxwiki · xwiki-platformEPSS 0.77%via NVD
CVE-2026-54688Medium· 6.5PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllow…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.50%via NVD
CVE-2026-54689Medium· 6.3PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is en…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVE-2026-55211Critical· 9.8
1w ago

Surfio is a library for reading and writing surface files

Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used t…

▾ Midnightequinor · surfioEPSS 0.74%via NVD
CVE-2026-55178High· 7.5
1w ago

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a…

▾ Twilightgeolens-io · geolensEPSS 0.65%via NVD
CVE-2026-55158Critical· 9.1
1w ago

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled …

▾ Midnightwktk · conflibotEPSS 0.80%via NVD
CVE-2026-53658Medium· 6.3
1w ago

Fabric CA is a Certificate Authority for Hyperledger Fabric

Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDA…

▾ Sunlithyperledger · fabric-caEPSS 0.45%via NVD
CVE-2026-53660High· 7.4
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and O…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.41%via NVD
CVE-2026-49446Medium· 6.1PoC
1w ago

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tu…

▾ Twilightazukaar · Cosmos-ServerEPSS 0.30%via NVD
CVE-2026-62263Critical· 9.2
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only …

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.86%via NVD
CVE-2026-62280Medium· 6.1
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl wi…

▾ SunlitOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-62379Critical· 9.8
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUti…

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 1.1%via NVD
CVE-2026-54561Medium· 6.2PoC
1w ago

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants

MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path …

▾ Twilightmkreyman · mcp-memory-keeperEPSS 0.25%via NVD
CVE-2026-54549High· 8.3PoC
1w ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, the upload_ad_image tool in meta_ads_mcp/core/ads.py passes an attacker-controlled image_url to try_multiple_download_m…

▾ Midnightpipeboard-co · meta-ads-mcpEPSS 0.40%via NVD
CVE-2026-54547High· 7.4PoC
1w ago

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_tok…

▾ Midnightpipeboard-co · meta-ads-mcpEPSS 0.52%via NVD
CVE-2026-54077High· 7.1
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integrat…

▾ TwilightArcadeData · arcadedbEPSS 0.45%via NVD
CVE-2026-54076High· 8.1
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcad…

▾ TwilightArcadeData · arcadedbEPSS 0.50%via NVD
CVE-2026-52724Medium· 5.8
1w ago

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer ve…

▾ Sunlitkumahq · kumaEPSS 0.35%via NVD
CVE-2026-50166Medium· 5.5
1w ago

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs

Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-ce…

▾ Sunlitkumahq · kumaEPSS 0.27%via NVD
CVEs tagged “ghsa” — page 13 · VulnSea