VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3811 CVEsRSS

CVE-2026-54788High· 7.5
1mo ago

dd-trace-rs provides Datadog application performance monitoring for Rust

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value…

▾ Twilightdatadog-opentelemetry · datadog-opentelemetryEPSS 0.79%via NVD
CVE-2026-54766Medium
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplica…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.43%via NVD
CVE-2026-55064Medium· 4.3
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project can detach it from its parent hierarchy by submitting parent_project_id equal to…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.37%via NVD
CVE-2026-55065High· 8.1
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only a…

▾ Twilightapi · code.vikunja.io/apiEPSS 0.50%via NVD
CVE-2026-55066High· 7.1
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket…

▾ Twilightapi · code.vikunja.io/apiEPSS 0.37%via NVD
CVE-2026-55067Medium· 5.0
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/model…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.34%via NVD
CVE-2026-55068Critical
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum va…

▾ Midnightfree5gc · github.com/free5gc/free5gcEPSS 0.59%via NVD
CVE-2026-55511Critical· 9.1PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

▾ Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVE-2026-55521High· 8.8
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and T…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.52%via NVD
CVE-2026-55545Medium· 6.5
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.45%via NVD
CVE-2026-55547Medium· 4.3
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.jav…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.34%via NVD
CVE-2026-55549Medium· 6.5PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping b…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 1.3%via NVD
CVE-2026-55552High· 7.5
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CVE-2026-54746Medium· 6.4
1mo ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the…

▾ Sunlithatchet-dev · github.com/hatchet-dev/hatchetEPSS 0.37%via NVD
GHSA-2vh6-hw4j-32wwMedium· 6.5
1mo ago

gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)

▾ Sunlitgix-packetline · gix-packetlinevia GHSA
CVE-2026-55108High· 8.5
1mo ago

KubeVela is an open source application delivery platform

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, G…

▾ Twilightoam-dev · github.com/oam-dev/kubevelaEPSS 0.75%via NVD
CVE-2026-54757High· 7.8
1mo ago

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.36%via OSV
CVE-2026-37004Critical· 9.8
1mo ago

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

▾ Midnightlitellm · litellmEPSS 0.80%via OSV
CVE-2026-81725Medium· 5.9
1mo ago

nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)

A flaw was found in NLTK, specifically within the Pl196xCorpusReader component. A remote attacker can exploit this by supplying malformed Text Encoding Initiative (TEI) blocks containing numerous unmatched opening tags. This triggers a reg…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.37%via CSAF
CVE-2026-81724High· 7.5⚖ disputed
1mo ago

nltk: NLTK: Denial of Service via Uncontrolled Recursion (CVE-2026-81724)

A flaw was found in NLTK. This uncontrolled recursion vulnerability in `nltk.featstruct.FeatStructReader` allows unauthenticated attackers to cause a denial of service. Attackers can achieve this by supplying deeply nested feature-structur…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.46%via CSAF
CVE-2026-81723Low· 3.7
1mo ago

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to caus…

▾ Sunlitnltk · nltkEPSS 0.28%via NVD
CVE-2026-81726High· 8.7
1mo ago

nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)

A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.34%via CSAF
CVE-2026-81727High· 7.1
1mo ago

nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)

A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installa…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.19%via CSAF
CVE-2026-81722High· 7.5
1mo ago

nltk: nltk PorterStemmer: Denial of Service due to inefficient token processing (CVE-2026-81722)

A flaw was found in the nltk PorterStemmer component. A remote attacker could exploit this vulnerability by providing a specially crafted, untrusted token. The inefficient algorithmic complexity in the stemming process, specifically within…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.52%via CSAF
CVE-2026-54687Critical· 9.8
1mo ago

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workf…

▾ Midnightdangerblack · n8n-node-sqlite3EPSS 0.58%via NVD
CVE-2026-42350Low
1mo ago

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter

▾ Sunlitakuity · github.com/akuity/kargoEPSS 0.41%via GHSA
CVE-2026-54718High· 7.2
1mo ago

Silverstripe Advanced Workflow is a highly configurable step-based workflow module

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side te…

▾ Twilightsymbiote · symbiote/silverstripe-advancedworkflowEPSS 1.0%via NVD
CVE-2026-54732Medium· 6.5
1mo ago

libreoffice-convert is a Node.js module for converting office documents to different formats

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base n…

▾ Sunlitlibreoffice-convert · libreoffice-convertEPSS 0.42%via NVD
GHSA-mf7q-r4rv-jv94High
1mo ago

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

▾ Twilightcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
CVE-2026-54720Medium· 5.4
1mo ago

Silverstripe Framework: Possible XSS attack through media embed

Silverstripe Framework: Possible XSS attack through media embed

▾ Sunlitsilverstripe · silverstripe/frameworkEPSS 0.26%via GHSA
CVEs tagged “ghsa” — page 29 · VulnSea