VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-8q49-2h5h-434xMedium· 5.9
2mo ago

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller

▾ Sunlitfrontmcp · @frontmcp/adaptersvia GHSA
GHSA-6vch-q96h-7gc3High
2mo ago

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
GHSA-pvcr-8mvp-w8qrHigh· 7.7
2mo ago

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-cr7p-cr3q-h5cmMedium· 5.3
2mo ago

Budibase: Account Enumeration via Login Lockout Response Differential

Budibase: Account Enumeration via Login Lockout Response Differential

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-pmpg-2mxq-6xwrHigh· 7.1
2mo ago

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-v42f-v8xc-j435High· 8.5
2mo ago

Budibase: SSRF via DNS rebinding in the REST datasource integration

Budibase: SSRF via DNS rebinding in the REST datasource integration

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hfhx-w8p8-4hc7Medium
2mo ago

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-94p4-4cq8-9g67High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-g3hq-hphg-8fhhHigh· 8.8
2mo ago

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

▾ Twilightpheditor · pheditor/pheditorvia GHSA
GHSA-68r5-9hpg-7qw9Critical· 9.4
2mo ago

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-dsml-servletvia GHSA
GHSA-p279-2cqp-84jgCritical· 9.6
2mo ago

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-server-legacyvia GHSA
GHSA-c534-2w9c-x7fmMedium· 6.5
2mo ago

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

▾ Sunlitzxh326 · github.com/zxh326/kitevia GHSA
GHSA-g5vv-q72c-7j78High· 7.5
2mo ago

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

▾ Twilightanephenix · @anephenix/hubvia GHSA
GHSA-26gq-p25f-99cpHigh
2mo ago

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow

▾ Twilightfatedier · github.com/fatedier/frpvia GHSA
GHSA-f45q-w629-wr25Medium
2mo ago

Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects

Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects

▾ Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-qqc3-94qv-7fw3Medium
2mo ago

Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic

Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic

▾ Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-2625-rw7m-5q5xLow
2mo ago

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

▾ Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-47w6-gwp4-w6vcHigh
2mo ago

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

▾ Twilightvantage6 · vantage6via GHSA
GHSA-v6w6-358x-2433Medium· 5.4
2mo ago

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4via GHSA
GHSA-vh45-f885-3848Critical· 9.1
2mo ago

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock

▾ Midnightsm-crypto · sm-cryptovia GHSA
CVE-2026-64785Medium· 5.3
2mo ago

swift-nio-http2: Missing CR/LF/NUL validation in header values

swift-nio-http2: Missing CR/LF/NUL validation in header values

▾ Sunlitswift-nio-http2 · swift-nio-http2EPSS 0.29%via GHSA
GHSA-f25v-x6vr-962gCritical· 10.0
2mo ago

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

▾ Midnightpheditor · pheditor/pheditorvia GHSA
GHSA-h4hf-v6w5-897xHigh· 8.8
2mo ago

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-rm67-g9ch-vxffHigh· 8.1
2mo ago

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-cmwh-g2h8-c222High· 8.1
2mo ago

Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-mhvj-jhpq-885vHigh· 7.4
2mo ago

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser

▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-46q4-43ph-c6frHigh· 7.4
2mo ago

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)

▾ Twilighthttp4s · org.http4s:blaze-http_2.13via GHSA
GHSA-7ppr-r889-mcf2High· 7.5
2mo ago

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

blaze: Unbounded WebSocket message aggregation in http4s-blaze-server

▾ Twilighthttp4s · org.http4s:http4s-blaze-server_2.13via GHSA
GHSA-95cv-r8x4-vh75High· 7.6
2mo ago

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal

▾ TwilightOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
GHSA-p6ph-3jx2-3337Medium· 4.3
2mo ago

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
CVEs tagged “ghsa” — page 63 · VulnSea