VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3811 CVEsRSS

CVE-2026-56681High· 7.3PoC
6d ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when i…

▾ Midnight9router · 9routerEPSS 0.97%via NVD
CVE-2026-63374Critical· 9.3
6d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library…

▾ Midnightagronholm · anyioEPSS 0.29%via NVD
CVE-2026-61652High· 8.7
1w ago

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=…

▾ Twilightkap-sh · zaprosEPSS 0.44%via NVD
CVE-2026-61541Medium· 6.9
1w ago

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…

▾ Sunlitkap-sh · zaprosEPSS 0.43%via NVD
GHSA-jhjp-4c2q-xmx4Medium· 4.3
1w ago

k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers

k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers

▾ Sunlitfalcosecurity · github.com/falcosecurity/plugins/plugins/k8sauditvia OSV
CVE-2026-61647High· 7.1
1w ago

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-t…

▾ Twilightroomi-fields · notebooklm-mcpEPSS 0.32%via NVD
CVE-2026-58272Medium· 5.3PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accou…

▾ TwilightSync-in · serverEPSS 0.34%via NVD
CVE-2026-58270Medium· 6.5PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic…

▾ TwilightSync-in · serverEPSS 0.35%via NVD
CVE-2026-58269High· 8.1PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full a…

▾ MidnightSync-in · serverEPSS 0.22%via NVD
CVE-2026-58271Medium· 6.8PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOT…

▾ TwilightSync-in · serverEPSS 0.22%via NVD
CVE-2026-69190Medium· 6.3
1w ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareReque…

▾ SunlitGraylog2 · graylog2-serverEPSS 0.42%via NVD
CVE-2026-62369High· 8.1
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…

▾ Twilightkubeedge · kubeedgeEPSS 0.86%via NVD
CVE-2026-61612Medium· 5.7
1w ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS…

▾ Sunlitondata · ckan-mcp-serverEPSS 0.23%via NVD
CVE-2026-62182High· 8.8
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/config…

▾ Twilightkubeedge · kubeedgeEPSS 0.48%via NVD
CVE-2026-77561Medium· 5.3PoC
1w ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…

▾ Twilighttinyauthapp · tinyauthEPSS 0.60%via NVD
CVE-2026-63116High· 8.8PoC
1w ago

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When…

▾ MidnightdeepstreamIO · deepstream.ioEPSS 0.51%via NVD
CVE-2026-62866Medium· 6.2PoC
1w ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the s…

▾ TwilightTomWright · daselEPSS 0.19%via NVD
CVE-2026-62371High· 8.8
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…

▾ Twilightkubeedge · kubeedgeEPSS 0.48%via NVD
CVE-2026-62370Medium· 6.5
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…

▾ Sunlitkubeedge · kubeedgeEPSS 0.50%via NVD
CVE-2026-59168Medium· 6.2
1w ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, …

▾ SunlitTomWright · daselEPSS 0.13%via NVD
CVE-2026-62987Medium· 5.8PoC
1w ago

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

▾ Twilightfabiolb · fabioEPSS 0.20%via NVD
CVE-2026-77582Medium· 6.9PoC
1w ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…

▾ Twilighttinyauthapp · tinyauthEPSS 0.48%via NVD
CVE-2026-77560High· 8.1
1w ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

▾ Twilighttinyauthapp · tinyauthEPSS 0.61%via NVD
CVE-2026-61681Medium· 4.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.Unsub…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-63342Medium· 6.3
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-ta…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-84298Low· 3.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map …

▾ Sunlithatchet-dev · hatchetEPSS 0.24%via NVD
CVE-2026-88978Medium· 4.3
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …

▾ Sunlithatchet-dev · hatchetEPSS 0.28%via NVD
CVE-2026-61687High· 7.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

▾ Twilighthatchet-dev · hatchetEPSS 0.17%via NVD
CVE-2026-71543High· 7.2
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.42%via NVD
CVE-2026-61628High· 8.1PoC
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the …

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.43%via NVD
CVEs tagged “ghsa” — page 6 · VulnSea