VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3811 CVEsRSS

CVE-2026-71553High
3w ago

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

▾ Twilightapostrophe · apostropheEPSS 0.43%via GHSA
CVE-2026-18504Medium· 5.4PoC
3w ago

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

▾ Twilightfastify · fastifyEPSS 0.31%via GHSA
CVE-2026-59834High· 7.5
3w ago

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-59832High· 7.7
3w ago

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.46%via OSV
GHSA-p498-v437-472gMedium
3w ago

humanfs: Recursive copy follows symlinked files and copies data from outside the source tree

humanfs: Recursive copy follows symlinked files and copies data from outside the source tree

▾ Sunlithumanfs · @humanfs/nodevia GHSA
GHSA-cvhv-g4rq-3hmwLow· 3.3
3w ago

ImageMagick: Memory Leak when providing invalid options to the cli

ImageMagick: Memory Leak when providing invalid options to the cli

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-12876Medium
3w ago

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars

▾ Sunlitnltk · nltkvia OSV
GHSA-cp6q-959q-f8rhMedium
3w ago

Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes

▾ Sunlittiptap · @tiptap/corevia GHSA
CVE-2026-52833High· 8.0
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runti…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.55%via NVD
CVE-2026-52832Medium· 4.9PoC
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.56%via NVD
CVE-2026-53600Medium
3w ago

async-tar is a tar archive reading/writing library for async Rust

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) …

▾ Sunlitasync-tar · async-tarEPSS 0.45%via NVD
CVE-2026-52831High· 8.0⚖ disputed
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.53%via NVD
CVE-2026-49832High· 8.0
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible …

▾ Twilightdspace · org.dspace:dspace-apiEPSS 0.87%via NVD
CVE-2026-49831Medium· 5.5
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r param…

▾ Sunlitdspace · org.dspace:dspace-apiEPSS 0.53%via NVD
CVE-2026-49830Medium· 4.4
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the …

▾ Sunlitdspace · org.dspace:dspace-apiEPSS 0.49%via NVD
CVE-2026-49833Medium· 5.5
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability is possible…

▾ Sunlitdspace · org.dspace:dspace-apiEPSS 0.37%via NVD
CVE-2026-53649Critical· 9.6
3w ago

Joro is a web exploitation framework

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelis…

▾ MidnightBishopFox · github.com/BishopFox/joroEPSS 0.33%via NVD
CVE-2026-84375High· 7.5
3w ago

js-yaml is a JavaScript YAML parser and dumper

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias…

▾ Twilightjs-yaml · js-yamlEPSS 0.53%via NVD
CVE-2026-84370High· 8.2
3w ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions …

▾ Twilightsvgo · svgoEPSS 0.53%via NVD
CVE-2026-84369Medium· 6.1
3w ago

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions …

▾ Sunlitsvgo · svgoEPSS 0.43%via NVD
CVE-2026-84365Medium· 6.5
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the c…

▾ Sunlithono · honoEPSS 0.44%via NVD
CVE-2026-84364Medium· 5.3
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the n…

▾ Sunlithono · honoEPSS 0.53%via NVD
CVE-2026-84363Medium· 5.9
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read r…

▾ Sunlithono · honoEPSS 0.45%via NVD
CVE-2026-84361HighPoC
3w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url…

▾ Midnightcomposer · composer/composerEPSS 0.55%via NVD
CVE-2026-84308Medium· 6.3
3w ago

phpseclib is a PHP secure communications library

phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). D…

▾ Sunlitphpseclib · phpseclibEPSS 0.33%via NVD
CVE-2026-84374High· 7.5
3w ago

Laravel Excel provides supercharged Excel exports and imports in Laravel

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::…

▾ Twilightmaatwebsite · maatwebsite/excelEPSS 0.84%via NVD
CVE-2026-84373Medium· 5.9
3w ago

Vitest is a testing framework powered by Vite

Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:regi…

▾ Sunlitvitest · @vitest/mockerEPSS 0.53%via NVD
CVE-2026-84367Low· 3.7
3w ago

joi is a schema description language and data validator for JavaScript

joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a r…

▾ Sunlitjoi · joiEPSS 0.39%via NVD
CVE-2026-84303Medium
3w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are…

▾ Sunlitgrpc · google.golang.org/grpcEPSS 0.31%via NVD
CVE-2026-83607High· 8.1
3w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement(tagName) stores…

▾ Twilightxmldom · @xmldom/xmldomEPSS 0.61%via NVD
CVEs tagged “ghsa” — page 24 · VulnSea