VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3816 CVEsRSS

CVE-2026-53509Medium· 5.7
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to a…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.38%via NVD
CVE-2026-47735High
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The …

▾ Twilightbasekick-labs · github.com/basekick-labs/arcEPSS 0.43%via NVD
CVE-2026-47753Medium
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission …

▾ Sunlitlxc · github.com/lxc/incus/v7EPSS 0.15%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVE-2026-49360High
1mo ago

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL …

▾ Twilightrecce · recceEPSS 1.1%via NVD
CVE-2026-44517Medium· 6.3
1mo ago

Buildah is a tool that facilitates building OCI images

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded build context, and downloadToDirector…

▾ Sunlitcontainers · github.com/containers/buildahEPSS 0.18%via NVD
CVE-2026-35163Medium
1mo ago

OctoPrint provides a web interface for controlling consumer 3D printers

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/…

▾ SunlitOctoPrint · OctoPrintEPSS 0.20%via NVD
CVE-2026-48749Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fi…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48750Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `e…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48751Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlev…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.64%via NVD
CVE-2026-48752Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command executio…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48753Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary co…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48754Low
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volu…

▾ Sunlitlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.38%via NVD
CVE-2026-48755Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary fi…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48756Low
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of…

▾ Sunlitlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.38%via NVD
CVE-2026-48769Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary com…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-53541Medium· 4.3
1mo ago

OliveTin gives access to predefined shell commands from a web interface

OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prio…

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 0.38%via NVD
CVE-2026-71485Critical· 9.1
1mo ago

Centrifugo is an open-source scalable real-time messaging server

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…

▾ Midnightcentrifugal · github.com/centrifugal/centrifugoEPSS 0.61%via NVD
CVE-2026-61625Medium· 6.8
1mo ago

VictoriaMetrics is a scalable solution for monitoring and managing time series data

VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/bac…

▾ SunlitVictoriaMetrics · github.com/VictoriaMetrics/VictoriaMetricsEPSS 0.40%via NVD
CVE-2026-71428Critical· 9.3
1mo ago

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…

▾ Midnightunstructured · unstructuredEPSS 0.44%via NVD
CVE-2026-67446Medium· 5.3⚖ disputed
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{i…

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.51%via NVD
CVE-2026-67445Medium· 5.3⚖ disputed
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses the verb or the RFC …

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.51%via NVD
CVE-2026-63481Medium
1mo ago

Hurl is a command line tool that runs and tests HTTP requests defined in plain text files

Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth cre…

▾ Sunlithurl · hurlEPSS 0.66%via NVD
CVE-2026-63490High· 7.5
1mo ago

Handlebars.java provides logic-less and semantic Mustache templates with Java

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…

▾ Twilightgithub · com.github.jknack:handlebars-springmvcEPSS 0.69%via NVD
CVE-2026-65842High· 8.2
1mo ago

Plate is a rich-text editor with AI and shadcn/ui

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can…

▾ Twilightplatejs · @platejs/docx-ioEPSS 0.52%via NVD
CVE-2026-68921Medium· 4.7
1mo ago

DiceBear is an avatar library for designers and developers

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, whil…

▾ Sunlitdicebear · @dicebear/coreEPSS 0.29%via NVD
CVE-2026-61704High· 7.5
1mo ago

Link Preview JS extracts web links information

Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public …

▾ Twilightlink-preview-js · link-preview-jsEPSS 0.55%via NVD
CVE-2026-71492Medium· 6.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…

▾ Sunlitbanks · banksEPSS 0.47%via NVD
CVE-2026-55558Medium· 5.9
1mo ago

aiosmtplib is an asynchronous SMTP client for use with asyncio

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. A…

▾ Sunlitaiosmtplib · aiosmtplibEPSS 0.40%via NVD
CVE-2026-54770Medium· 6.1
1mo ago

WebOb provides objects for HTTP requests and responses

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.42%via NVD
CVEs tagged “ghsa” — page 36 · VulnSea