Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-8q49-2h5h-434xMedium· 5.9FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-6vch-q96h-7gc3Highetcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-pvcr-8mvp-w8qrHigh· 7.7Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-cr7p-cr3q-h5cmMedium· 5.3Budibase: Account Enumeration via Login Lockout Response Differential
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-pmpg-2mxq-6xwrHigh· 7.1Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-v42f-v8xc-j435High· 8.5Budibase: SSRF via DNS rebinding in the REST datasource integration
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-hfhx-w8p8-4hc7MediumBudibase: SSRF via bare fetch() in uploadUrl during AI table generation
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-94p4-4cq8-9g67High· 7.5GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-g3hq-hphg-8fhhHigh· 8.8Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-p279-2cqp-84jgCritical· 9.6OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
GHSA-c534-2w9c-x7fmMedium· 6.5Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
GHSA-g5vv-q72c-7j78High· 7.5@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-26gq-p25f-99cpHighfrp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-f45q-w629-wr25MediumHubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-qqc3-94qv-7fw3MediumHubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-2625-rw7m-5q5xLowHubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GHSA-v6w6-358x-2433Medium· 5.4Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
GHSA-vh45-f885-3848Critical· 9.1sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
CVE-2026-64785Medium· 5.3swift-nio-http2: Missing CR/LF/NUL validation in header values
swift-nio-http2: Missing CR/LF/NUL validation in header values
GHSA-f25v-x6vr-962gCritical· 10.0Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
GHSA-h4hf-v6w5-897xHigh· 8.8Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
GHSA-rm67-g9ch-vxffHigh· 8.1Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
GHSA-cmwh-g2h8-c222High· 8.1Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
GHSA-mhvj-jhpq-885vHigh· 7.4blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-46q4-43ph-c6frHigh· 7.4blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA-7ppr-r889-mcf2High· 7.5blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-95cv-r8x4-vh75High· 7.6OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-p6ph-3jx2-3337Medium· 4.3OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search