VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-69248High· 7.4
1mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate h…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.31%via NVD
CVE-2026-16729Medium· 4.8
1mo ago

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

▾ Sunlitundici · undiciEPSS 0.19%via GHSA
CVE-2026-14643Medium· 5.9
1mo ago

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

▾ Sunlitundici · undiciEPSS 0.40%via GHSA
CVE-2026-15157Medium· 4.2
1mo ago

undici vulnerable to CRLF Injection via blob-like body 'type' property

undici vulnerable to CRLF Injection via blob-like body 'type' property

▾ Sunlitundici · undiciEPSS 0.19%via GHSA
CVE-2026-69198Medium
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's ow…

▾ Sunlitip-address · ip-addressEPSS 0.48%via NVD
CVE-2026-69192High· 8.6
1mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, an…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.66%via NVD
GHSA-3f7w-8rr8-f37fHigh· 8.1
1mo ago

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-539m-9xh6-q6rrMedium· 6.5
1mo ago

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

▾ SunlitGitPython · GitPythonvia GHSA
GHSA-p538-c434-8v24Medium· 5.4
1mo ago

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

▾ SunlitGitPython · GitPythonvia GHSA
CVE-2026-69185High· 7.5
1mo ago

Socket.IO enables bidirectional and low-latency communication for every platform

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, w…

▾ Twilightsocket.io-parser · socket.io-parserEPSS 0.63%via NVD
CVE-2026-13697High· 7.4
1mo ago

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

▾ Twilightundici · undiciEPSS 0.57%via GHSA
CVE-2026-16728Medium· 4.8
1mo ago

undici vulnerable to downstream response desynchronization via retry interceptor

undici vulnerable to downstream response desynchronization via retry interceptor

▾ Sunlitundici · undiciEPSS 0.18%via GHSA
CVE-2026-69152High· 7.5
1mo ago

brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152)

A flaw was found in the brace-expansion library. The `expand()` function does not apply `maxLength` when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block …

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2026-69153High· 7.5
1mo ago

postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and exp…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.45%via CSAF
CVE-2026-68930Medium· 6.5
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, an…

▾ Sunlitrussh · russhEPSS 0.38%via NVD
CVE-2026-68945High· 8.2
1mo ago

@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache (CVE-2026-68945)

A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP requests during server-side rendering, incorrectly generates cache keys when repeated request parameters are present, causing semantically dif…

▾ TwilightRed Hat · Red Hat Ceph Storage 4EPSS 0.18%via CSAF
CVE-2026-69149High
1mo ago

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)

▾ Twilightangular · @angular/platform-serverEPSS 0.35%via GHSA
CVE-2026-69151High
1mo ago

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

▾ Twilightangular · @angular/compilerEPSS 0.33%via GHSA
CVE-2026-8763High· 7.4
1mo ago

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.…

▾ TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.45%via NVD
CVE-2026-48031Critical· 9.1
1mo ago

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public …

▾ Midnightdhax · github.com/dhax/go-baseEPSS 0.63%via NVD
CVE-2026-48061Medium· 5.9
1mo ago

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whiteli…

▾ Sunlitlitestar · litestarEPSS 0.38%via NVD
CVE-2026-48063Critical
1mo ago

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…

▾ Midnightbaileys · baileysEPSS 0.22%via NVD
CVE-2026-48113High
1mo ago

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The …

▾ Twilightjpillora · github.com/jpillora/chiselEPSS 0.39%via NVD
GHSA-6r2r-ww24-7h52High· 8.8
1mo ago

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-3mcp-22mf-vrw3Medium· 7.5
1mo ago

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

▾ Sunlitaxios · axiosvia GHSA
GHSA-m4f3-g4cq-hqrxHigh· 7.5
1mo ago

Duplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

Duplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-cw2r-r7mw-j3hcCritical· 9.8
1mo ago

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

▾ Midnightgitpython · gitpythonvia GHSA
GHSA-4vpg-pfj8-m33qHigh· 8.4
1mo ago

Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-32rq-jhr7-m3hhMedium· 5.3
1mo ago

Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers

Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-3fvr-2jw6-crq4Medium· 5.3
1mo ago

Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service

Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service

▾ Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
CVEs tagged “ghsa” — page 56 · VulnSea