VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-65841Medium
2mo ago

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SV…

▾ Sunlitjodit · joditEPSS 0.53%via NVD
CVE-2026-53510High· 8.1
2mo ago

Savon is a Ruby SOAP client

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. Thi…

▾ Twilightsavon · savonEPSS 0.69%via NVD
CVE-2026-53466Medium· 6.5
2mo ago

ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow

ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.37%via GHSA
CVE-2026-53599High· 7.5
2mo ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/…

▾ Twilightredaxo · redaxo/sourceEPSS 0.51%via NVD
CVE-2026-52887Critical· 10.0PoC
2mo ago

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE

▾ Abyssalnocobase · @nocobase/plugin-notification-in-app-messageEPSS 0.89%via GHSA
GHSA-3whf-vgf2-9w6gMedium
2mo ago

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

▾ Sunlitzaino-state · zaino-statevia GHSA
CVE-2026-53500High· 8.2
2mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist.…

▾ Twilightthumbor · thumborEPSS 0.50%via NVD
CVE-2026-53501High· 8.2
2mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() …

▾ Twilightthumbor · thumborEPSS 0.35%via NVD
CVE-2026-53503High· 7.5
2mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C extension (thumbor/ext/filter…

▾ Twilightthumbor · thumborEPSS 0.75%via NVD
CVE-2026-53504High· 7.5
2mo ago

Thumbor is an open-source photo thumbnail service by globo.com

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing t…

▾ Twilightthumbor · thumborEPSS 0.61%via NVD
CVE-2026-55100High
2mo ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query …

▾ Twilighthashi-vault-js · hashi-vault-jsEPSS 0.56%via NVD
CVE-2026-54725Critical· 9.6
2mo ago

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, M…

▾ Midnightbank-vaults · github.com/bank-vaults/vault-secrets-webhookEPSS 0.45%via NVD
CVE-2026-54737High· 7.3
2mo ago

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, a…

▾ Twilightphun-ky · @phun-ky/defaults-deepEPSS 0.46%via NVD
GHSA-xrmj-5g4g-8987Medium· 4.2
2mo ago

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
GHSA-p7w7-4929-vpj5High· 7.5
2mo ago

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation

▾ Twilightdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-52857Medium· 5.5
2mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configur…

▾ Sunlitpterodactyl · github.com/pterodactyl/wingsEPSS 0.16%via NVD
CVE-2026-52855Critical· 9.9
2mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{co…

▾ Midnightpterodactyl · github.com/pterodactyl/wingsEPSS 0.51%via NVD
CVE-2026-52856High· 7.5
2mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

▾ Twilightpterodactyl · github.com/pterodactyl/wingsEPSS 0.61%via NVD
CVE-2026-54707Medium· 5.4
2mo ago

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files sett…

▾ Sunlitonionshare-cli · onionshare-cliEPSS 0.40%via NVD
CVE-2026-54706Medium· 4.8
2mo ago

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/sen…

▾ Sunlitonionshare-cli · onionshare-cliEPSS 0.34%via NVD
CVE-2026-54753Medium· 5.9
2mo ago

`nx graph` dev server permissive CORS policy

`nx graph` dev server permissive CORS policy

▾ Sunlitnx · nxEPSS 1.2%via GHSA
CVE-2026-12074High· 7.5
2mo ago

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nlt…

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

▾ Twilightnltk · nltkvia OSV
CVE-2026-12072High· 7.5
2mo ago

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (E…

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

▾ Twilightnltk · nltkvia OSV
CVE-2026-12061High· 7.5
2mo ago

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex

▾ Twilightnltk · nltkvia OSV
CVE-2026-12075High· 8.6
2mo ago

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORC…

Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode

▾ Twilightnltk · nltkvia OSV
CVE-2026-65834Medium· 6.8
2mo ago

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

▾ Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.47%via GHSA
CVE-2026-65835Medium· 6.6
2mo ago

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

▾ Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.33%via GHSA
CVE-2026-54729High
2mo ago

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no addres…

▾ Twilightdssrf · dssrfEPSS 0.48%via NVD
GHSA-pqh8-p93p-2rx7Medium· 4.3
2mo ago

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-55495Medium· 4.3
2mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape th…

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.38%via NVD
CVEs tagged “ghsa” — page 58 · VulnSea