Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-hr66-5mqr-8mpxHigh· 7.5Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-gh4h-34gr-87r7Medium· 5.7Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
GHSA-qw6m-8fw2-2v64High· 8.3Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-2xgg-r2wc-c5r2High· 7.6Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
CVE-2026-55404High· 7.5yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
GHSA-fjr4-x663-mwxcHigh· 8.1GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
GHSA-6p8h-3wgx-97gfHigh· 7.5GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
GHSA-r9mr-m37c-5fr3High· 8.8GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
CVE-2026-15074High· 7.5@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
CVE-2026-7120Medium· 5.3@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
GHSA-464c-974j-9xm6Low· 3.3AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
GHSA-qwww-vcr4-c8h2HighReact Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
GHSA-5xvq-cp9x-6p6rMedium· 5.3Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
GHSA-cqjc-rmpq-xprqMedium· 4.3Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
GHSA-g9hv-x236-4qp3Medium· 5.3Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
GHSA-pm4m-ph32-ghv5High· 7.5js-yaml: Exponential parsing time in flow collections leads to denial of service
js-yaml: Exponential parsing time in flow collections leads to denial of service
GHSA-gcjh-h69q-9w9gMediumcel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
GHSA-r277-6w6q-xmqwCritical· 9.1kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
GHSA-mfg7-5gfp-c4w3Medium· 5.3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
GHSA-v74w-7mr3-4qg3High· 7.5Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
CVE-2026-55607HighClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
CVE-2026-59214High· 7.3Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-59218Medium· 5.3Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-59226Low· 3.1Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVE-2026-59220Medium· 6.5Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVE-2026-59227Medium· 4.3Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVE-2026-59715Low· 3.1Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVE-2026-59219High· 7.1Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVE-2026-59217Medium· 4.3Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
CVE-2026-59213Low· 3.5Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)