VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-50569Medium· 4.3
2mo ago

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

▾ Sunlitfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-50567High· 7.7
2mo ago

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

▾ Twilightfission · github.com/fission/fissionEPSS 0.45%via GHSA
CVE-2026-50568Low· 3.6
2mo ago

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

▾ Sunlitfission · github.com/fission/fissionEPSS 0.14%via GHSA
CVE-2026-49447Medium· 5.3
2mo ago

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens

▾ Sunlitazukaar · github.com/azukaar/cosmos-serverEPSS 0.38%via GHSA
CVE-2026-54588Critical· 9.6
2mo ago

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

▾ Midnightpoweradmin · poweradmin/poweradminEPSS 0.54%via GHSA
CVE-2026-54635High· 7.5
2mo ago

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

▾ Twilightpytonapi · pytonapiEPSS 0.71%via GHSA
CVE-2026-54593High· 8.1
2mo ago

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

▾ Twilightpterodactyl · pterodactyl/panelEPSS 0.68%via GHSA
GHSA-hc4m-q9jh-xw4jMedium· 6.6
2mo ago

nono-cli'scregistry pack verification can fail open when provenance metadata is absent

nono-cli'scregistry pack verification can fail open when provenance metadata is absent

▾ Sunlitnono-cli · nono-clivia GHSA
CVE-2026-54345Medium
2mo ago

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via OSV
CVE-2026-54332Medium
2mo ago

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS

▾ Sunlitgopacket · github.com/gopacket/gopacketEPSS 0.79%via GHSA
CVE-2026-54619Low
2mo ago

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity

▾ Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.14%via GHSA
CVE-2026-54620Low
2mo ago

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

▾ Sunlitsqlite3-ruby · sqlite3-rubyEPSS 0.14%via GHSA
CVE-2026-54605High· 7.2
2mo ago

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…

▾ Twilightoauth · oauthEPSS 0.19%via NVD
CVE-2026-54603High· 8.6
2mo ago

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC)

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority,…

▾ Twilightoauth2 · oauth2EPSS 0.59%via NVD
CVE-2026-54609High· 8.6
2mo ago

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

▾ Twilightquietterminal · com.quietterminal:qti-neonEPSS 0.46%via GHSA
CVE-2026-54545High· 7.1
2mo ago

@wakaru/cli arbitrary file write during bundle unpack

@wakaru/cli arbitrary file write during bundle unpack

▾ Twilightwakaru · @wakaru/cliEPSS 0.20%via GHSA
CVE-2026-55771High· 8.8
2mo ago

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.57%via GHSA
CVE-2026-61609High· 7.5
2mo ago

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)

▾ Twilightpterodactyl · pterodactyl/panelEPSS 0.74%via GHSA
GHSA-vg6v-j97m-h5xqMedium· 6.8
2mo ago

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition

▾ Sunlitnovu · @novu/application-genericvia GHSA
CVE-2026-43983High
2mo ago

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

▾ Twilightpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.36%via GHSA
GHSA-hp74-gm6m-2qm5Medium
2mo ago

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

▾ Sunlitpocket-id · github.com/pocket-id/pocket-id/backendvia GHSA
CVE-2026-43910High· 8.2
2mo ago

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

▾ Twilightappium · io.appium:java-clientEPSS 0.43%via GHSA
CVE-2026-45293High· 8.6
2mo ago

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rule…

▾ Twilightwp-coding-standards · wp-coding-standards/wpcsEPSS 0.25%via NVD
CVE-2026-47427High· 7.5
2mo ago

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler

▾ Twilightgithub · github.com/github/github-mcp-serverEPSS 0.77%via GHSA
CVE-2026-47219High· 7.5
2mo ago

find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)

A flaw was found in find-my-way, a routing module for Node.js. A remote attacker could exploit this vulnerability when find-my-way is used with Node's HTTP/2 server. By sending specially crafted HTTP/2 method values, an attacker can cause …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.46%via CSAF
CVE-2026-54272High· 7.2
2mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.43%via NVD
CVE-2023-37465Medium· 6.5
2mo ago

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

▾ Sunlitxwiki · org.xwiki.contrib:discussions-servervia GHSA
CVE-2026-55685Medium· 6.5
2mo ago

react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…

▾ SunlitRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
CVE-2026-45623High· 7.5
2mo ago

postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)

A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.61%via CSAF
GHSA-jpcw-4wr7-c3vqMedium· 5.3
2mo ago

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema

▾ Sunlitgetkin · github.com/getkin/kin-openapivia GHSA
CVEs tagged “ghsa” — page 62 · VulnSea