VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-55253High· 7.7
2w ago

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search()…

▾ Twilightlangchain-ai · langchain-mongodbEPSS 0.53%via NVD
CVE-2026-54723Medium· 6.5
2w ago

devpi is a Python package index staging server and packaging, testing, and release tool

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +…

▾ Sunlitdevpi · devpiEPSS 0.43%via NVD
CVE-2026-55209Critical· 9.8
2w ago

resdata is software for reading and writing result files from the Eclipse reservoir simulator

resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while parsing untrusted GRD…

▾ Midnightequinor · resdataEPSS 0.78%via NVD
CVE-2026-53659High· 7.5
2w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompress…

▾ Twilighthttp4k · http4kEPSS 0.63%via NVD
CVE-2026-53752High· 7.5
2w ago

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files

docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn sty…

▾ Twilightplutext · docx4jEPSS 0.63%via NVD
CVE-2026-53708Medium· 6.6PoC
2w ago

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…

▾ TwilightIBM · mcp-context-forgeEPSS 0.35%via NVD
CVE-2026-55102Medium· 5.8
2w ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosEr…

▾ Sunlitkyndryl-open-source · hashi-vault-jsEPSS 0.16%via NVD
CVE-2026-55072High· 8.5PoC
2w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…

▾ Midnightpimcore · pimcoreEPSS 0.41%via NVD
CVE-2026-54632High· 7.5
2w ago

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted b…

▾ Twilightsipsorcery-org · sipsorceryEPSS 0.72%via NVD
CVE-2026-57497Medium· 5.3
2w ago

webtransport-go is an implementation of the WebTransport protocol

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, …

▾ Sunlitquic-go · webtransport-goEPSS 0.52%via NVD
CVE-2026-54559Medium· 6.9
2w ago

PocketSphinx is a small speech recognizer

PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loader…

▾ Sunlitcmusphinx · pocketsphinxEPSS 0.55%via NVD
CVE-2026-54246Medium· 5.7
2w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/s…

▾ Sunlitzalando · skipperEPSS 0.34%via NVD
CVE-2026-53496Medium· 5.3PoC
2w ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where f…

▾ Twilightmattiasw · ExifReaderEPSS 0.51%via NVD
CVE-2026-54567High· 7.5PoC
2w ago

Flask-Reuploaded provides file uploads for Flask

Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension hel…

▾ Midnightjugmac00 · flask-reuploadedEPSS 0.63%via NVD
CVE-2026-54247Medium· 4.3
2w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly …

▾ Sunlitzalando · skipperEPSS 0.30%via NVD
CVE-2026-54541Low· 3.7
2w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk proof containing two Trie…

▾ Sunlitnimiq-primitives · nimiq-primitivesEPSS 0.44%via NVD
CVE-2026-54542Low· 3.7
2w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk whose proof contains a Tr…

▾ Sunlitnimiq · core-rs-albatrossEPSS 0.44%via NVD
CVE-2026-53718Medium· 6.4
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resour…

▾ Sunlitenvoyproxy · gatewayEPSS 0.41%via NVD
CVE-2026-53716Medium· 6.5
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without l…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53719Medium· 6.5
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a n…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53717Medium· 6.5
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53715Medium· 5.3
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…

▾ Sunlitenvoyproxy · gatewayEPSS 0.47%via NVD
CVE-2026-53713Critical· 9.1
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…

▾ Midnightenvoyproxy · gatewayEPSS 0.43%via NVD
CVE-2026-53714High· 7.4
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

▾ Twilightenvoyproxy · gatewayEPSS 0.35%via NVD
CVE-2026-50270High· 7.5
2w ago

dd-trace-java is a Datadog APM client for Java

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…

▾ TwilightDataDog · dd-trace-javaEPSS 0.79%via NVD
CVE-2026-50276High· 7.5
2w ago

dd-trace-rb is Datadog's client library for Ruby

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…

▾ TwilightDataDog · dd-trace-rbEPSS 0.79%via NVD
CVE-2026-54452Medium· 6.3
2w ago

safeurl is a server-side request forgery protection library

safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIP…

▾ Sunlitdoyensec · safeurlEPSS 0.52%via NVD
CVE-2026-54447High· 8.4
2w ago

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token directory and garmin_tokens.json without explicit ow…

▾ Twilightcyberjunky · python-garminconnectEPSS 0.15%via NVD
CVE-2026-54087High· 7.6
2w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline s…

▾ TwilightEasyCorp · EasyAdminBundleEPSS 0.40%via NVD
CVE-2026-54628High· 8.6PoC
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVEs tagged “ghsa” — page 17 · VulnSea