Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-65841MediumJodit Editor is a WYSIWYG editor with a built-in file browser & image editor
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SV…
CVE-2026-53510High· 8.1Savon is a Ruby SOAP client
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. Thi…
CVE-2026-53466Medium· 6.5ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
CVE-2026-53599High· 7.5REDAXO is a PHP-based content management system
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/…
CVE-2026-52887Critical· 10.0PoCNocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
GHSA-3whf-vgf2-9w6gMediumzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
CVE-2026-53500High· 8.2Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist.…
CVE-2026-53501High· 8.2Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() …
CVE-2026-53503High· 7.5Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filter…
CVE-2026-53504High· 7.5Thumbor is an open-source photo thumbnail service by globo.com
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing t…
CVE-2026-55100Highhashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …
CVE-2026-54725Critical· 9.6vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, M…
CVE-2026-54737High· 7.3@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, a…
GHSA-xrmj-5g4g-8987Medium· 4.2@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
GHSA-p7w7-4929-vpj5High· 7.5`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
CVE-2026-52857Medium· 5.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configur…
CVE-2026-52855Critical· 9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{co…
CVE-2026-52856High· 7.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
CVE-2026-54707Medium· 5.4OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files sett…
CVE-2026-54706Medium· 4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/sen…
CVE-2026-54753Medium· 5.9`nx graph` dev server permissive CORS policy
`nx graph` dev server permissive CORS policy
CVE-2026-12074High· 7.5Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nlt…
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
CVE-2026-12072High· 7.5Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (E…
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
CVE-2026-12061High· 7.5Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
CVE-2026-12075High· 8.6Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORC…
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
CVE-2026-65834Medium· 6.8Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
CVE-2026-65835Medium· 6.6Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
CVE-2026-54729HighDSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no addres…
GHSA-pqh8-p93p-2rx7Medium· 4.3@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
CVE-2026-55495Medium· 4.3Cloudreve is a self-hosted file management and sharing system
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape th…