VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-55496Medium· 4.3
2mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to …

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.36%via NVD
CVE-2026-55497Medium· 6.5
2mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to subm…

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.53%via NVD
CVE-2026-55499Medium· 4.3
2mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authentic…

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.33%via NVD
CVE-2026-55502High· 7.1
2mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id value…

▾ Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.34%via NVD
CVE-2026-62323Medium· 6.3
2mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or comp…

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.31%via NVD
CVE-2026-45086Medium· 5.4
2mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor w…

▾ Sunlitdecidim-demographics · decidim-demographicsEPSS 0.29%via NVD
CVE-2026-45330Medium· 4.9
2mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier wi…

▾ Sunlitdecidim-verifications · decidim-verificationsEPSS 0.46%via NVD
CVE-2026-45376Medium· 5.5
2mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity ex…

▾ Sunlitdecidim-admin · decidim-adminEPSS 0.60%via NVD
CVE-2026-45377Medium· 6.5
2mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resul…

▾ Sunlitdecidim-core · decidim-coreEPSS 0.45%via NVD
CVE-2026-59881Medium· 5.3
2mo ago

aiohttp: AIOHTTP: Denial of Service via unnegotiated WebSocket compression (CVE-2026-59881)

A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sendin…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.52%via CSAF
CVE-2026-68500High· 7.5
2mo ago

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId paramete…

▾ Twilightsylius · sylius/mollie-pluginEPSS 0.68%via NVD
CVE-2026-68501Medium· 6.5
2mo ago

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCode…

▾ Sunlitsylius · sylius/mollie-pluginEPSS 0.60%via NVD
CVE-2026-68499Medium· 6.2
2mo ago

re2 provides Node.js bindings for Google's RE2 regular expression engine

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor …

▾ Sunlitre2 · re2EPSS 0.18%via NVD
CVE-2026-67550Medium· 5.7
2mo ago

re2 provides Node.js bindings for Google's RE2 regular expression engine

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and spl…

▾ Sunlitre2 · re2EPSS 0.16%via NVD
CVE-2026-66066CriticalPoC
2mo ago

Action Pack is a framework for handling and responding to web requests

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload …

▾ Abyssalactivestorage · activestorageEPSS 2.1%via NVD
CVE-2026-54722High
2mo ago

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the …

▾ Twilightdssrf · dssrfEPSS 0.57%via NVD
CVE-2026-54522Low
2mo ago

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure

▾ Sunlitmsgpack · msgpackEPSS 0.23%via GHSA
CVE-2026-67437High· 7.5
2mo ago

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

▾ TwilightOliveTin · github.com/OliveTin/OliveTinEPSS 0.64%via GHSA
CVE-2026-67439Medium· 4.3
2mo ago

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 0.43%via GHSA
CVE-2026-67438Medium· 6.6
2mo ago

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 1.6%via GHSA
CVE-2026-63118Medium
2mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

▾ Sunlitmcp · mcpEPSS 0.26%via GHSA
CVE-2026-63119Medium· 6.2
2mo ago

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)

▾ Sunlitmcp · mcpEPSS 0.18%via GHSA
CVE-2026-67430Medium· 5.3
2mo ago

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

▾ Sunlitmcp · mcpEPSS 0.51%via GHSA
CVE-2026-67432High· 7.5
2mo ago

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport

▾ Twilightmcp · mcpEPSS 0.78%via GHSA
CVE-2026-67431High
2mo ago

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

▾ Twilightmcp · mcpEPSS 0.48%via GHSA
CVE-2026-67435Medium
2mo ago

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.50%via GHSA
CVE-2026-67429Critical· 10.0
2mo ago

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

▾ Midnightflyto-core · flyto-coreEPSS 0.77%via GHSA
CVE-2026-67427High· 8.6
2mo ago

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

▾ Twilightflyto-core · flyto-coreEPSS 0.59%via GHSA
CVE-2026-67425High· 8.6
2mo ago

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

▾ Twilightflyto-core · flyto-coreEPSS 0.56%via GHSA
CVE-2026-67426Critical· 9.3
2mo ago

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

▾ Midnightflyto-core · flyto-coreEPSS 0.51%via GHSA
CVEs tagged “ghsa” — page 59 · VulnSea