VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3811 CVEsRSS

CVE-2026-76910Medium· 5.3PoC
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the s…

▾ TwilightUnleash · unleashEPSS 0.30%via NVD
CVE-2026-76909Low· 2.1
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTit…

▾ SunlitUnleash · unleashEPSS 0.27%via NVD
CVE-2026-77426High· 7.1
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting …

▾ TwilightUnleash · unleashEPSS 0.48%via NVD
CVE-2026-77425Medium· 4.3PoC
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUp…

▾ TwilightUnleash · unleashEPSS 0.23%via NVD
CVE-2026-63627Medium· 6.9
6d ago

mppx is a TypeScript interface for machine payments protocol

mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could …

▾ Sunlitwevm · mppxEPSS 0.38%via NVD
CVE-2026-63628Medium· 6.9PoC
6d ago

mppx is a TypeScript interface for machine payments protocol

mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 FeePayerEnvelope without validating its length…

▾ Twilightwevm · mppxEPSS 0.38%via NVD
CVE-2026-83805Medium· 6.4
6d ago

Nautobot is a Network Source of Truth and Network Automation Platform

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under re…

▾ Sunlitnautobot · nautobotEPSS 0.22%via NVD
CVE-2026-83801Medium· 5.4
6d ago

Nautobot is a Network Source of Truth and Network Automation Platform

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, an…

▾ Sunlitnautobot · nautobotEPSS 0.22%via NVD
CVE-2026-79767Medium· 5.5
6d ago

Gardener implements the automated management and operation of Kubernetes clusters as a service

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check com…

▾ Sunlitgardener · gardenerEPSS 0.39%via NVD
CVE-2026-77322High· 7.5PoC
6d ago

SIPGO is a library for writing SIP services in the GO language

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length…

▾ Midnightemiago · sipgoEPSS 0.52%via NVD
CVE-2026-65829Medium· 5.3
6d ago

MPXJ is an open source library to read and write project plans from a variety of file formats and databases

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbit…

▾ Sunlitjoniles · mpxjEPSS 0.34%via NVD
CVE-2026-61570High· 7.5
6d ago

MPXJ is an open source library to read and write project plans from a variety of file formats and databases

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS …

▾ Twilightsf · net.sf.mpxj:mpxjEPSS 0.35%via NVD
CVE-2026-59991High· 7.5PoC
6d ago

psd-tools is a Python package for working with Adobe Photoshop PSD files

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels…

▾ Midnightpsd-tools · psd-toolsEPSS 0.52%via NVD
CVE-2026-62985High· 7.5PoC
6d ago

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rej…

▾ Midnightazu · request-filtering-agentEPSS 0.46%via NVD
CVE-2026-58268High· 7.5
6d ago

SIPGO is a library for writing SIP services in the GO language

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is…

▾ Twilightemiago · sipgoEPSS 0.61%via NVD
CVE-2026-91130Critical· 9.3PoC
6d ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and compu…

▾ Abyssalhomeassistant · homeassistantEPSS 0.39%via NVD
CVE-2026-91129Medium· 5.4PoC
6d ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ip…

▾ Twilighthome-assistant · coreEPSS 0.20%via NVD
CVE-2026-57149Critical· 9.9
6d ago

plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone

plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic por…

▾ Midnightplone · plone.app.portletsEPSS 0.64%via NVD
CVE-2026-77257High· 8.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restric…

▾ Twilightsooperset · mcp-atlassianEPSS 0.40%via NVD
CVE-2026-77262High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for…

▾ Midnightsooperset · mcp-atlassianEPSS 0.54%via NVD
CVE-2026-77255High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementa…

▾ Midnightsooperset · mcp-atlassianEPSS 0.40%via NVD
CVE-2026-77269Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachmen…

▾ Twilightsooperset · mcp-atlassianEPSS 0.38%via NVD
CVE-2026-77266Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server w…

▾ Twilightmcp-atlassian · mcp_atlassianEPSS 0.47%via NVD
CVE-2026-77272Medium· 5.4
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an …

▾ Sunlitmcp-atlassian · mcp_atlassianEPSS 0.24%via NVD
CVE-2026-77247High· 8.3PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files befo…

▾ Midnightsooperset · mcp-atlassianEPSS 0.45%via NVD
CVE-2026-77268Medium· 5.5
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processe…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.11%via NVD
CVE-2026-77259High· 7.7PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains …

▾ Midnightsooperset · mcp-atlassianEPSS 0.39%via NVD
CVE-2026-77249Medium· 5.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead of the fetcher's protecte…

▾ Sunlitmcp-atlassian · mcp-atlassianEPSS 0.33%via NVD
CVE-2026-77253High· 7.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atla…

▾ Midnightmcp-atlassian · mcp_atlassianEPSS 0.40%via NVD
CVE-2026-77248High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while up…

▾ Midnightmcp-atlassian · mcp_atlassianEPSS 0.42%via NVD
CVEs tagged “ghsa” — page 4 · VulnSea