VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-73080Critical· 9.3
1mo ago

SeaweedFS is a distributed storage system

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the …

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 0.53%via NVD
CVE-2026-48790Medium· 5.5
1mo ago

Turso CLI is the command line interface (CLI) to the open-source database Turso

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credenti…

▾ Sunlittursodatabase · github.com/tursodatabase/turso-cliEPSS 0.15%via NVD
CVE-2026-48809High· 7.5
1mo ago

python-engineio is a Python implementation of the Engine.IO realtime client and server

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before …

▾ Twilightpython-engineio · python-engineioEPSS 0.49%via NVD
CVE-2026-48802High· 7.5
1mo ago

python-engineio is a Python implementation of the Engine.IO realtime client and server

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbe…

▾ Twilightpython-engineio · python-engineioEPSS 0.57%via NVD
CVE-2026-48804High· 7.5
1mo ago

python-socketio is a Python implementation of the Socket.IO realtime client and server

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attach…

▾ Twilightpython-socketio · python-socketioEPSS 0.49%via NVD
CVE-2026-48813LowPoC
1mo ago

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Inj…

▾ Twilightflawfinder · flawfinderEPSS 0.44%via NVD
CVE-2026-69112High· 7.1
1mo ago

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…

▾ Twilightaccelerate · accelerateEPSS 0.19%via NVD
CVE-2026-8798High
1mo ago

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

Bouncy Castle: the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound

▾ Twilightbouncycastle · org.bouncycastle:bc-fipsEPSS 0.43%via GHSA
CVE-2026-13505High· 7.5
1mo ago

org.bouncycastle/bc-fips: Bouncy Castle for Java FIPS: Sensitive key material remains in memory due to delayed zeroisation (CVE-2026-13505)

A flaw was found in Bouncy Castle for Java FIPS (BC-FJA). Sensitive cryptographic key material, intended to be securely erased from memory (zeroised) upon garbage collection, may persist longer than expected. This occurs because the zerois…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform Expansion PackEPSS 0.25%via CSAF
CVE-2026-69127Medium
1mo ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauth…

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.51%via NVD
CVE-2026-76217Medium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Sunlitgitpython · gitpythonEPSS 0.41%via OSV
CVE-2026-71870Medium
1mo ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses unusually large source-code or destination-string tokens in a fo…

▾ Sunlitpypdf · pypdfEPSS 0.18%via NVD
CVE-2026-15895High· 7.8
1mo ago

jsii-diff: Command Injection via npm: package argument

jsii-diff: Command Injection via npm: package argument

▾ Twilightjsii-diff · jsii-diffEPSS 1.1%via GHSA
CVE-2026-71847Low
1mo ago

Ruby JSON is a JSON implementation for Ruby

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves state.start, state.cursor, and state.end pointing into released stora…

▾ Sunlitjson · jsonEPSS 0.43%via NVD
CVE-2026-71848Medium· 5.3
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language ta…

▾ Sunlithono · honoEPSS 0.51%via NVD
CVE-2026-71849Low· 3.7
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RF…

▾ Sunlithono · honoEPSS 0.36%via NVD
CVE-2026-71850Medium· 4.8
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and…

▾ Sunlithono · honoEPSS 0.27%via NVD
CVE-2026-71851Critical· 9.0PoC
1mo ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …

▾ Abyssalcrypto-js · crypto-jsEPSS 0.55%via NVD
CVE-2026-56818Medium· 6.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…

▾ Sunlitnetty · nettyEPSS 0.47%via NVD
CVE-2026-71556High· 7.1
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resoluti…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.36%via NVD
CVE-2026-71557Medium· 6.3PoC
1mo ago

go-git is an extensible git implementation library written in pure Go

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciou…

▾ Twilightgo-git · github.com/go-git/go-git/v5EPSS 0.41%via NVD
GHSA-7c4v-fwgw-9rf7Medium
1mo ago

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

▾ Sunlitnuxt · nuxtvia GHSA
CVE-2026-66062Medium· 5.3
1mo ago

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular exp…

▾ Sunlitsveltejs · @sveltejs/kitEPSS 0.51%via NVD
CVE-2026-54164Medium· 6.5
1mo ago

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

▾ Sunlitapi-platform · api-platform/coreEPSS 0.34%via GHSA
GHSA-55q2-fjhq-7xh7Medium
1mo ago

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-4gmw-gg2m-w46pHigh· 8.1
1mo ago

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-9rj7-rf2p-w77rHigh· 7.5
1mo ago

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-hh9p-6wh2-4mfcMedium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ SunlitGitPython · GitPythonvia GHSA
GHSA-hmq2-w58f-27jcHigh· 8.2
1mo ago

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-jm78-9fvv-mhgrHigh· 8.8
1mo ago

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

▾ TwilightGitPython · GitPythonvia GHSA
CVEs tagged “ghsa” — page 49 · VulnSea