VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-67428High· 8.5
2mo ago

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

▾ Twilightflyto-core · flyto-coreEPSS 0.45%via GHSA
CVE-2026-67424High· 8.5
2mo ago

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

▾ Twilightflyto-core · flyto-coreEPSS 0.41%via GHSA
CVE-2026-54693High
2mo ago

ZITADEL Users Can Self-Verify Email/Phone via API

ZITADEL Users Can Self-Verify Email/Phone via API

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.58%via GHSA
CVE-2026-54680Critical· 9.9
2mo ago

Logging operator automates the deployment and configuration of Kubernetes logging pipelines

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record…

▾ Midnightkube-logging · github.com/kube-logging/logging-operatorEPSS 0.78%via NVD
GHSA-xvg2-cgv6-6h7vHigh
2mo ago

netfoil: Incorrect block responses could lead to localhost traffic

netfoil: Incorrect block responses could lead to localhost traffic

▾ Twilighttinfoil-factory · github.com/tinfoil-factory/netfoilvia GHSA
GHSA-pmwx-rm49-xv39Low
2mo ago

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal

▾ Sunlitactiverecord-tenanted · activerecord-tenantedvia GHSA
CVE-2026-54712Medium· 5.3
2mo ago

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

OpenTelemetry Javaagent RMI context propagation allows resource exhaustion

▾ Sunlitopentelemetry · io.opentelemetry.javaagent:opentelemetry-javaagentEPSS 0.46%via GHSA
CVE-2026-54704Medium· 6.5
2mo ago

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

▾ Sunlitopentelemetry · io.opentelemetry.javaagent:opentelemetry-javaagentEPSS 0.38%via GHSA
CVE-2026-54705Medium· 6.3
2mo ago

mathlive's Lack of Escaping of HTML allows for XSS

mathlive's Lack of Escaping of HTML allows for XSS

▾ Sunlitmathlive · mathliveEPSS 0.36%via GHSA
CVE-2026-54735Critical· 10.0
2mo ago

prebid-server's request forgery vulnerability allows for possible host environment data extraction

prebid-server's request forgery vulnerability allows for possible host environment data extraction

▾ Midnightprebid · github.com/prebid/prebid-server/v4EPSS 0.61%via GHSA
CVE-2026-11393High· 9.0
2mo ago

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

▾ Twilightaws · @aws/agentcoreEPSS 0.34%via GHSA
GHSA-wchh-9x6h-7f6pMedium
2mo ago

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

▾ Sunlitmatrix-commander · matrix-commandervia GHSA
CVE-2026-55651High· 7.1
2mo ago

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure

▾ Twilightalextselegidis · alextselegidis/easyappointmentsEPSS 0.32%via GHSA
CVE-2026-52840Low· 2.7
2mo ago

Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.31%via GHSA
CVE-2026-52839Low· 3.3
2mo ago

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.23%via GHSA
CVE-2026-52837Medium
2mo ago

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.56%via GHSA
CVE-2026-52841Low· 3.1
2mo ago

Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.21%via GHSA
CVE-2026-52838Low· 2.6
2mo ago

Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.24%via GHSA
CVE-2026-54574High· 8.2
2mo ago

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

▾ Twilightproot-distro · proot-distroEPSS 0.19%via GHSA
CVE-2026-54727High· 8.2
2mo ago

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

▾ Twilightproot-distro · proot-distroEPSS 0.18%via GHSA
CVE-2026-54079High
2mo ago

veraPDF Validation XXE via XFA

veraPDF Validation XXE via XFA

▾ Twilightverapdf · org.verapdf:validation-modelEPSS 0.56%via GHSA
CVE-2026-54078High
2mo ago

veraPDF Validation XXE via Rich Text

veraPDF Validation XXE via Rich Text

▾ Twilightverapdf · org.verapdf:validation-modelEPSS 0.56%via GHSA
CVE-2026-54082Medium· 6.5
2mo ago

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs

▾ Sunlitverapdf · org.verapdf:validation-modelEPSS 0.40%via GHSA
CVE-2026-54080Medium
2mo ago

veraPDF Parser DoS via PostScript CMap Streams

veraPDF Parser DoS via PostScript CMap Streams

▾ Sunlitverapdf · org.verapdf:parserEPSS 0.52%via GHSA
CVE-2026-54081Medium
2mo ago

veraPDF Parser DoS via PostScript Type 1 Font Programs

veraPDF Parser DoS via PostScript Type 1 Font Programs

▾ Sunlitverapdf · org.verapdf:parserEPSS 0.52%via GHSA
CVE-2026-49755High
2mo ago

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

▾ Twilightreq · reqEPSS 0.70%via GHSA
CVE-2026-49756Medium
2mo ago

Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type

Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type

▾ Sunlitreq · reqEPSS 0.34%via GHSA
CVE-2026-50558Medium· 5.9
2mo ago

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote…

▾ Sunlitpenelope-shell-handler · penelope-shell-handlerEPSS 0.37%via NVD
GHSA-pc2w-4mq8-32qwLow· 3.7
2mo ago

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-54660High· 7.4
2mo ago

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.44%via GHSA
CVEs tagged “ghsa” — page 60 · VulnSea