VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3820 CVEsRSS

CVE-2026-52734Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/compo…

▾ Sunlitzebrad · zebradEPSS 0.51%via NVD
CVE-2026-52817High
1mo ago

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get…

▾ Twilightlinuxfabrik-lib · linuxfabrik-libEPSS 0.18%via NVD
CVE-2026-52829High· 7.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized …

▾ Twilightzebra-network · zebra-networkEPSS 0.61%via NVD
CVE-2026-52731Medium· 6.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-r…

▾ Sunlitzebra-rpc · zebra-rpcEPSS 0.53%via NVD
CVE-2026-52732Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/memp…

▾ Sunlitzebrad · zebradEPSS 0.51%via NVD
CVE-2026-52854High· 8.6
1mo ago

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays p…

▾ Twilightmediawiki · mediawiki/mapsEPSS 0.58%via NVD
CVE-2026-50138High· 8.1
1mo ago

goshs is a SimpleHTTPServer written in Go

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP po…

▾ Twilightgoshs · goshs.de/goshs/v2EPSS 0.38%via NVD
CVE-2026-50139Medium· 5.9
1mo ago

goshs is a SimpleHTTPServer written in Go

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent r…

▾ Sunlitgoshs · goshs.de/goshs/v2EPSS 0.26%via NVD
CVE-2026-50143High· 8.1
1mo ago

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the tru…

▾ Twilightapify · @apify/actors-mcp-serverEPSS 0.49%via NVD
CVE-2026-48796Medium· 5.3
1mo ago

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsW…

▾ SunlitCefSharp · CefSharp.CommonEPSS 0.40%via NVD
CVE-2026-48508High· 8.8
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION…

▾ Twilightlemur · lemurEPSS 0.33%via NVD
CVE-2026-55162Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in crl_verify and ocsp_verify without adequat…

▾ Sunlitlemur · lemurEPSS 0.22%via NVD
CVE-2026-55163Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member of the target role.…

▾ Sunlitlemur · lemurEPSS 0.22%via NVD
CVE-2026-55164Medium· 4.9
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Be…

▾ Sunlitlemur · lemurEPSS 0.29%via NVD
CVE-2026-55165Medium· 4.8
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that attacker-controlled value to decode_wit…

▾ Sunlitlemur · lemurEPSS 0.15%via NVD
CVE-2026-55166Critical· 9.9
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend req…

▾ Midnightlemur · lemurEPSS 0.29%via NVD
CVE-2026-73560Medium· 6.5
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through _fetch…

▾ Sunlitvllm · vllmvia NVD
CVE-2026-19693High· 8.1
1mo ago

extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.28%via CSAF
CVE-2026-71486Medium· 4.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choice…

▾ Sunlitvllm · vllmEPSS 0.47%via NVD
CVE-2026-63669Medium· 6.5
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the chec…

▾ Sunlitapostrophe · apostropheEPSS 0.31%via NVD
CVE-2026-63670Medium· 6.1
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a li…

▾ Sunlitsanitize-html · sanitize-htmlEPSS 0.33%via NVD
CVE-2026-63667Medium· 6.5
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and ex…

▾ Sunlitapostrophecms · @apostrophecms/import-exportEPSS 0.46%via NVD
CVE-2026-54356High· 7.1PoC
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-…

▾ Midnightbudibase · @budibase/serverEPSS 0.35%via NVD
GHSA-xhcr-cqfr-m3hvHigh
1mo ago

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-j659-8xh6-5pq5High
1mo ago

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-mpwr-8vm7-h73fMedium
1mo ago

package pkcs12: Authentication bypass in Decode functions

package pkcs12: Authentication bypass in Decode functions

▾ Sunlitsrc · software.sslmate.com/src/go-pkcs12via GHSA
CVE-2026-53766Medium· 6.1
1mo ago

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.12%via GHSA
CVE-2026-56677High· 8.6
1mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…

▾ Twilight9router · 9routerEPSS 0.38%via NVD
CVE-2026-64849High· 8.5CISA KEVPoC
1mo ago

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …

A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…

▾ AbyssalRed Hat · Red Hat OpenShift AI 3.4EPSS 9.8%via CSAF
CVE-2026-69146Medium· 6.5
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…

▾ Sunlitmlflow · mlflowEPSS 0.39%via NVD
CVEs tagged “ghsa” — page 44 · VulnSea