VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-75899High· 7.5
1mo ago

fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)

A flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-75975High· 7.5
1mo ago

fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)

A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a mal…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-75931High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion via skipped IDN canonicalization (CVE-2026-75931)

A flaw was found in fast-uri, a URI parser for Node.js. This vulnerability arises because the parser fails to consistently convert internationalized domain names (IDN) to their standard ASCII form when processing scheme-relative references…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVE-2026-77567High· 8.1
1mo ago

Filament is a collection of full-stack components for accelerated Laravel development

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when …

▾ Twilightfilament · filament/filamentEPSS 0.55%via NVD
GHSA-vx2m-jpxr-xv7wMedium· 5.3
1mo ago

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-w8j7-39hp-8x59Medium
1mo ago

Cloudreve's remote download file paths can escape the selected destination directory

Cloudreve's remote download file paths can escape the selected destination directory

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-fx4f-mhw4-qm7jMedium
1mo ago

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

▾ Sunlitvibeio-http · vibeio-httpvia GHSA
GHSA-4ph6-mjv7-3fq6Low
1mo ago

netfoil vulnerable to improper handling of untrusted DoH response data

netfoil vulnerable to improper handling of untrusted DoH response data

▾ Sunlittinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
GHSA-w67g-5rqw-f597Medium
1mo ago

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

▾ Sunlitgorilla · github.com/gorilla/websocketvia GHSA
CVE-2026-55477High· 7.2
1mo ago

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

▾ Twilightmhsanaei · github.com/mhsanaei/3x-ui/v3EPSS 0.61%via GHSA
CVE-2026-54049High· 8.7
1mo ago

Sakai Conversations has a Stored XSS Issue

Sakai Conversations has a Stored XSS Issue

▾ Twilightsakaiproject · org.sakaiproject.conversations:sakai-conversations-implvia GHSA
GHSA-5x78-73v4-xg6wHigh
1mo ago

postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

▾ Twilightpostgres-protocol · postgres-protocolvia GHSA
GHSA-rgqc-3x5p-6gwgMedium
1mo ago

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

▾ Sunlitpostgres-protocol · postgres-protocolvia GHSA
GHSA-3gjw-f78c-vvpwMedium
1mo ago

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

▾ Sunlittokio-postgres · tokio-postgresvia GHSA
CVE-2026-45404Medium
1mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe fo…

▾ Sunlitotel · go.opentelemetry.io/otel/bridge/opentracingEPSS 0.14%via NVD
GHSA-qp76-pq9f-gr9mHigh· 5.9
1mo ago

Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4

Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4

▾ Twilightnltk · nltkvia GHSA
CVE-2026-70626Medium· 6.2
1mo ago

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does no…

▾ Sunlitnltk · nltkEPSS 0.20%via NVD
CVE-2026-65915Medium· 6.5
1mo ago

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to…

▾ Sunlitnltk · nltkEPSS 0.41%via NVD
CVE-2026-63312High· 7.5
1mo ago

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open()

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can r…

▾ Twilightnltk · nltkEPSS 0.65%via NVD
CVE-2026-63310High· 7.1
1mo ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.12%via NVD
CVE-2026-62385Medium· 5.9
1mo ago

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attac…

▾ Sunlitnltk · nltkEPSS 0.42%via NVD
CVE-2026-62384High· 7.5
1mo ago

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators i…

▾ Twilightnltk · nltkEPSS 0.65%via NVD
CVE-2026-62383Medium· 5.5
1mo ago

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitra…

▾ Sunlitnltk · nltkEPSS 0.18%via NVD
GHSA-486p-g8x4-77mgMedium· 7.1
1mo ago

Duplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat

Duplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat

▾ Sunlitonnx · onnxvia GHSA
CVE-2026-71494Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a…

▾ Sunlitinfracost · github.com/infracost/infracostEPSS 0.50%via NVD
CVE-2026-71493Medium
1mo ago

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go use a lexical filepath.Rel …

▾ Sunlitinfracost · github.com/infracost/infracostEPSS 0.54%via NVD
CVE-2026-62675High· 8.8
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle…

▾ Twilightomnigent · omnigentEPSS 0.65%via NVD
CVE-2026-62674Critical· 9.0
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template ag…

▾ Midnightomnigent · omnigentEPSS 0.51%via NVD
CVE-2026-62677High· 8.8
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value beca…

▾ Twilightomnigent · omnigentEPSS 0.61%via NVD
CVE-2026-62676High· 7.1
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the ti…

▾ Twilightomnigent · omnigentEPSS 0.40%via NVD
CVEs tagged “ghsa” — page 34 · VulnSea