Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2026-39831High· 8.1golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check (CVE-2026-39831)
A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardw…
CVE-2026-42508Critical· 9.1Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-39834Medium· 6.5⚖ disputedInvoking infinite loop on large channel writes in golang.org/x/crypto/ssh
Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
CVE-2026-46595High· 7.1PoC⚖ disputedgolang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595)
A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This…
CVE-2026-8769Low· 4.3@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload
Grav is Vulnerable to XXE via SVG Upload
CVE-2026-42151High· 7.5Prometheus is an open-source monitoring system and time series database
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of…
CVE-2026-42027Critical· 9.8⚖ disputedArbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loa…
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method loa…
CVE-2026-33626High· 7.5PoCLMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVE-2026-56275Medium· 7.1Flowise Execute Flow function has an SSRF vulnerability
Flowise Execute Flow function has an SSRF vulnerability
CVE-2025-14813High· 7.5: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects B…
CVE-2026-56370Low· 3.3ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
ImageMagick has out-of-bounds access in ConnectedComponentsImage() via CLI-controlled connected-components:* artifacts
CVE-2026-32203High· 7.5.NET and Visual Studio Denial of Service Vulnerability
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-56762Medium· 5.3Hono missing validation of cookie name on write path in setCookie()
Hono missing validation of cookie name on write path in setCookie()
CVE-2026-56341High· 7.5AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-56346MediumAVideo has Unauthenticated PGP Message Decryption via Public Endpoint
AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
CVE-2026-30922High· 7.5PoCpyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)
An unbounded recursion flaw has been discovered in the pypi pyasn1 library. This uncontrolled recursion occurs when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing nested SEQUENCE (0x3…
CVE-2026-2092High· 7.7A flaw was found in Keycloak
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML asserti…
CVE-2026-56397MediumSiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
CVE-2026-32594MediumParse Server's GraphQL WebSocket endpoint bypasses security middleware
Parse Server's GraphQL WebSocket endpoint bypasses security middleware
CVE-2026-31887HighShopware: Unauthenticated data extraction possible through store-api.order endpoint
Shopware: Unauthenticated data extraction possible through store-api.order endpoint
CVE-2026-56315Critical· 9.8PickleScan has multiple stdlib modules with direct RCE not in blocklist
PickleScan has multiple stdlib modules with direct RCE not in blocklist
CVE-2026-56376Low· 3.7ImageMagick has a possible heap Use After Free vulnerability in its meta coder
ImageMagick has a possible heap Use After Free vulnerability in its meta coder
CVE-2026-26318High· 8.8Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
CVE-2020-36939High· 7.5PoCCassandra Web - Remote File Read
Cassandra Web - Remote File Read
CVE-2026-21884High· 8.2React Router is a router for React
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/stora…
CVE-2025-59057High· 7.6PoCReact Router is a router for React
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…
CVE-2025-61686Critical· 9.1PoCReact Router is a router for React
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…
CVE-2025-37731Medium· 6.8Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2025-67505High· 8.4Okta Java Management SDK facilitates interactions with the Okta management API
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response h…