Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-67428High· 8.5Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
CVE-2026-67424High· 8.5Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
CVE-2026-54693HighZITADEL Users Can Self-Verify Email/Phone via API
ZITADEL Users Can Self-Verify Email/Phone via API
CVE-2026-54680Critical· 9.9Logging operator automates the deployment and configuration of Kubernetes logging pipelines
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record…
GHSA-xvg2-cgv6-6h7vHighnetfoil: Incorrect block responses could lead to localhost traffic
netfoil: Incorrect block responses could lead to localhost traffic
GHSA-pmwx-rm49-xv39LowActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
CVE-2026-54712Medium· 5.3OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
CVE-2026-54704Medium· 6.5OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
CVE-2026-54705Medium· 6.3mathlive's Lack of Escaping of HTML allows for XSS
mathlive's Lack of Escaping of HTML allows for XSS
CVE-2026-54735Critical· 10.0prebid-server's request forgery vulnerability allows for possible host environment data extraction
prebid-server's request forgery vulnerability allows for possible host environment data extraction
CVE-2026-11393High· 9.0AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-wchh-9x6h-7f6pMediumolm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
CVE-2026-55651High· 7.1Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
CVE-2026-52840Low· 2.7Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
CVE-2026-52839Low· 3.3Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
CVE-2026-52837MediumEasy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
CVE-2026-52841Low· 3.1Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
CVE-2026-52838Low· 2.6Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
CVE-2026-54574High· 8.2`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
CVE-2026-54727High· 8.2proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
CVE-2026-54079HighveraPDF Validation XXE via XFA
veraPDF Validation XXE via XFA
CVE-2026-54078HighveraPDF Validation XXE via Rich Text
veraPDF Validation XXE via Rich Text
CVE-2026-54082Medium· 6.5veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
CVE-2026-54080MediumveraPDF Parser DoS via PostScript CMap Streams
veraPDF Parser DoS via PostScript CMap Streams
CVE-2026-54081MediumveraPDF Parser DoS via PostScript Type 1 Font Programs
veraPDF Parser DoS via PostScript Type 1 Font Programs
CVE-2026-49755HighReq vulnerable to unbounded archive/compression extraction triggered by response content-type
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
CVE-2026-49756MediumReq vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
CVE-2026-50558Medium· 5.9Penelope Shell Handler is a post-exploitation shell handler for authorized security testing
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote…
GHSA-pc2w-4mq8-32qwLow· 3.7@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`