VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-mqq9-gxg5-m58gHigh· 5.9
1mo ago

Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers

Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers

▾ Twilightguzzlehttp · guzzlehttp/guzzlevia GHSA
GHSA-mjrx-74jh-7xgwHigh· 5.9
1mo ago

Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved

Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved

▾ Twilightguzzlehttp · guzzlehttp/guzzlevia GHSA
CVE-2026-67325High· 8.8
1mo ago

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uplo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 2.2%via NVD
CVE-2026-67323High· 8.4
1mo ago

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

▾ TwilightGitPython · GitPythonEPSS 1.3%via NVD
CVE-2026-67322High· 7.5
1mo ago

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.33%via NVD
CVE-2026-67321Medium· 7.5
1mo ago

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serializati…

▾ Sunlitaxios · axiosEPSS 0.53%via NVD
CVE-2026-57232Low· 3.1
2mo ago

Contao is an Open Source CMS

Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs from FeedReaderController::getResponse() to feedIo->read() without scheme or priv…

▾ Sunlitcontao · contao/contaoEPSS 0.29%via NVD
CVE-2026-63220Medium· 4.8
2mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers an…

▾ Sunlitcodeigniter4 · codeigniter4/frameworkEPSS 0.17%via NVD
CVE-2026-63221Critical· 9.4
2mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled conditio…

▾ Midnightcodeigniter4 · codeigniter4/frameworkEPSS 0.61%via NVD
CVE-2026-63222High· 7.5
2mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to w…

▾ Twilightcodeigniter4 · codeigniter4/frameworkEPSS 0.64%via NVD
CVE-2026-55824Low· 2.6
2mo ago

Contao is an Open Source CMS

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler tries to prevent confidential HTTP client options from being sent to ext…

▾ Sunlitcontao · contao/contaoEPSS 0.24%via NVD
CVE-2026-18446High· 7.5
2mo ago

fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)

A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-54908Medium
2mo ago

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message

▾ Sunlitpion · github.com/pion/dtls/v3EPSS 0.54%via GHSA
CVE-2026-53573Medium
2mo ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…

▾ Sunlitgeonetwork-opensource · org.geonetwork-opensource:geonetworkEPSS 0.65%via NVD
CVE-2026-54768Medium
2mo ago

WPGraphQL provides a GraphQL API for WordPress sites

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordR…

▾ Sunlitwp-graphql · wp-graphql/wp-graphqlEPSS 0.45%via NVD
CVE-2026-54785Medium· 6.2
2mo ago

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI

gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining…

▾ Sunlitgemini-bridge · gemini-bridgeEPSS 0.19%via NVD
CVE-2016-1000305Medium
2mo ago

guard-livereload has a directory traversal vulnerability

guard-livereload has a directory traversal vulnerability

▾ Sunlitguard-livereload · guard-livereloadvia GHSA
CVE-2026-54910High· 7.7
2mo ago

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

▾ Twilightgtsteffaniak · github.com/gtsteffaniak/filebrowser/backendEPSS 0.46%via GHSA
CVE-2026-53606Medium· 5.4
2mo ago

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes

▾ Sunlitsanitize-html · sanitize-htmlEPSS 0.23%via GHSA
CVE-2026-53609Critical· 9.1
2mo ago

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass

▾ Midnightapostrophe · apostropheEPSS 0.38%via GHSA
CVE-2026-53607Low· 3.7
2mo ago

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header

▾ Sunlitapostrophe · apostropheEPSS 0.32%via GHSA
CVE-2026-53608High· 8.7
2mo ago

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag

▾ Twilightapostrophecms · @apostrophecms/seoEPSS 0.35%via GHSA
CVE-2026-54787Low· 3.1
2mo ago

sigstore-go is a Go library for Sigstore signing and verification

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without…

▾ Sunlitsigstore · github.com/sigstore/sigstore-goEPSS 0.13%via NVD
CVE-2026-54909Medium· 5.3
2mo ago

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

▾ Sunlitpion · github.com/pion/stun/v3EPSS 0.64%via OSV
CVE-2026-53551Medium
2mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control …

▾ Sunlitfree5gc · github.com/free5gc/free5gcEPSS 0.74%via NVD
CVE-2026-53505High· 7.5
2mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in the post-transform phase. An attacker can trigger extreme…

▾ Twilightthumbor · thumborEPSS 0.61%via NVD
CVE-2026-53502High
2mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH through watermark or f…

▾ Twilightthumbor · thumborEPSS 0.52%via NVD
CVE-2026-62324Medium· 5.4
2mo ago

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case…

▾ Sunlitjodit · joditEPSS 0.31%via NVD
CVE-2026-54756Medium
2mo ago

Jodit has prototype pollution via Jodit.configure() / ConfigMerge

Jodit has prototype pollution via Jodit.configure() / ConfigMerge

▾ Sunlitjodit · joditEPSS 0.46%via GHSA
CVE-2026-58263High· 7.2
2mo ago

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier

▾ Twilightjodit · joditEPSS 0.30%via GHSA
CVEs tagged “ghsa” — page 57 · VulnSea