VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-53553High· 7.7
4w ago

Goploy is an open-source automation deployment system

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by…

▾ Twilightzhenorzz · github.com/zhenorzz/goployEPSS 0.46%via NVD
CVE-2026-82333High· 7.5
1mo ago

multer: Multer: Denial of Service via oversized array index in field names (CVE-2026-82333)

A flaw was found in Multer, a Node.js middleware for handling multipart/form-data. A remote attacker can send a specially crafted multipart request containing oversized array indices in field names. This can cause Multer's field parser to …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.49%via CSAF
CVE-2026-77078High· 7.5PoC
1mo ago

multer: Multer: Denial of Service via crafted multipart field names (CVE-2026-77078)

A flaw was found in multer, a Node.js middleware for handling multipart/form-data. A remote attacker can send a small multipart request containing two specially crafted text field names. This can cause an uncaught error that terminates the…

▾ MidnightRed Hat · Red Hat Developer HubEPSS 0.49%via CSAF
CVE-2026-77063Low· 3.7
1mo ago

multer: Multer: File size limit bypass via asynchronous file filter race condition (CVE-2026-77063)

A flaw was found in multer, a software component used in Node.js applications to handle file uploads. When an application configures an asynchronous file filter along with a file size limit, a race condition can occur. This vulnerability a…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.23%via CSAF
CVE-2026-77037High· 7.5
1mo ago

multer: Multer: Denial of Service via file descriptor leak on aborted uploads (CVE-2026-77037)

A flaw was found in multer, a Node.js middleware for handling multipart/form-data. A remote attacker can exploit a file descriptor leak by sending repeated aborted or malformed multipart uploads. This can exhaust system resources, leading …

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.58%via CSAF
CVE-2026-55785Low· 3.7
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAk…

▾ Sunlitfree5gc · github.com/free5gc/ausfEPSS 0.45%via NVD
CVE-2026-55848High· 8.6
1mo ago

mapfish-print is a component of MapFish for printing templated cartographic maps

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print end…

▾ Twilightmapfish · org.mapfish.print:print-libEPSS 0.53%via NVD
CVE-2026-55843High· 6.5
1mo ago

Snipe-IT has an Improper Privilege Management issue

Snipe-IT has an Improper Privilege Management issue

▾ Twilightsnipe · snipe/snipe-itEPSS 0.54%via GHSA
CVE-2026-55856Medium· 5.9
1mo ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a pa…

▾ Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.44%via NVD
CVE-2026-55857Medium· 5.9
1mo ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insec…

▾ Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.39%via NVD
CVE-2026-55858Medium· 5.9
1mo ago

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the a…

▾ Sunlitmariadb · org.mariadb.jdbc:mariadb-java-clientEPSS 0.87%via NVD
CVE-2026-55859Medium· 5.9
1mo ago

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A s…

▾ Sunlitmariadb · org.mariadb:r2dbc-mariadbEPSS 0.49%via NVD
CVE-2026-55860Medium· 5.9
1mo ago

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the Authentication…

▾ Sunlitmariadb · org.mariadb:r2dbc-mariadbEPSS 0.23%via NVD
CVE-2026-55830High· 8.3
1mo ago

RestrictedPython guard hooks can be shadowed via positional-only arguments

RestrictedPython guard hooks can be shadowed via positional-only arguments

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.40%via OSV
CVE-2026-55855Medium· 6.5
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer param…

▾ Sunlitmariadb · mariadbEPSS 0.47%via NVD
CVE-2026-55854Medium· 5.9
1mo ago

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentica…

▾ Sunlitmariadb · mariadbEPSS 0.42%via NVD
CVE-2026-55764High
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/sy…

▾ Twilightklever-io · github.com/klever-io/klever-goEPSS 0.54%via NVD
CVE-2026-55841High· 7.5
1mo ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/c…

▾ Twilightgraylog2 · org.graylog2:graylog2-serverEPSS 0.63%via NVD
CVE-2026-55867Medium
1mo ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog…

▾ Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.56%via NVD
CVE-2026-55873Medium· 4.3
1mo ago

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

▾ Sunlitseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.34%via GHSA
CVE-2026-55779Medium· 5.4
1mo ago

Silverstripe Versioned provides versioning for Silverstripe models

Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Ti…

▾ Sunlitsilverstripe · silverstripe/versionedEPSS 0.34%via NVD
CVE-2026-55784High· 7.5
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, ke…

▾ Twilightfree5gc · github.com/free5gc/ausfEPSS 0.42%via NVD
CVE-2026-55891Low· 0.0
1mo ago

PrivateBin is an online pastebin where the server has zero knowledge of pasted data

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation …

▾ Sunlitprivatebin · privatebin/privatebinEPSS 0.54%via NVD
CVE-2026-55763High
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early…

▾ Twilightklever-io · github.com/klever-io/klever-goEPSS 0.51%via NVD
CVE-2026-55761High· 5.9
1mo ago

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

▾ Twilightportainer · github.com/portainer/portainerEPSS 0.49%via GHSA
CVE-2026-55678Medium
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not confi…

▾ Sunlitbasekick-labs · github.com/basekick-labs/arcEPSS 0.66%via NVD
CVE-2026-55696Medium· 4.3
1mo ago

PrivateBin is an online pastebin where the server has zero knowledge of pasted data

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobU…

▾ Sunlitprivatebin · privatebin/privatebinEPSS 0.37%via NVD
CVE-2026-55245High
1mo ago

Bifrost is an enterprise AI gateway for routing requests to model providers

Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, clas…

▾ Twilightmaximhq · github.com/maximhq/bifrost/coreEPSS 0.61%via NVD
CVE-2026-55584High· 7.5PoC
1mo ago

phpSysInfo is a customizable PHP script that displays system information

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A…

▾ Midnightphpsysinfo · phpsysinfo/phpsysinfoEPSS 1.9%via NVD
CVE-2026-55638High· 8.6
1mo ago

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass

▾ Twilight9router · 9routerEPSS 0.61%via GHSA
CVEs tagged “ghsa” — page 27 · VulnSea