VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-hr66-5mqr-8mpxHigh· 7.5
2mo ago

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-gh4h-34gr-87r7Medium· 5.7
2mo ago

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-qw6m-8fw2-2v64High· 8.3
2mo ago

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-2xgg-r2wc-c5r2High· 7.6
2mo ago

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector

▾ Twilightbudibase · @budibase/servervia GHSA
CVE-2026-55404High· 7.5
2mo ago

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

▾ Twilightyt-dlp · yt-dlpEPSS 0.64%via GHSA
GHSA-fjr4-x663-mwxcHigh· 8.1
2mo ago

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-6p8h-3wgx-97gfHigh· 7.5
2mo ago

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-r9mr-m37c-5fr3High· 8.8
2mo ago

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-15074High· 7.5
2mo ago

@fastify/static vulnerable to route guard bypass via path traversal

@fastify/static vulnerable to route guard bypass via path traversal

▾ Twilightfastify · @fastify/staticEPSS 0.67%via GHSA
CVE-2026-7120Medium· 5.3
2mo ago

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

▾ Sunlitfastify · @fastify/staticEPSS 0.37%via GHSA
GHSA-464c-974j-9xm6Low· 3.3
2mo ago

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

▾ Sunlitaws-cdk-lib · aws-cdk-libvia OSV
GHSA-qwww-vcr4-c8h2High
2mo ago

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

▾ Twilightreact-router · react-routervia GHSA
GHSA-5xvq-cp9x-6p6rMedium· 5.3
2mo ago

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

▾ Sunlitrussh · russhvia GHSA
GHSA-cqjc-rmpq-xprqMedium· 4.3
2mo ago

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

▾ Sunlitrussh · russhvia GHSA
GHSA-g9hv-x236-4qp3Medium· 5.3
2mo ago

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

▾ Sunlitrussh · russhvia GHSA
GHSA-pm4m-ph32-ghv5High· 7.5
2mo ago

js-yaml: Exponential parsing time in flow collections leads to denial of service

js-yaml: Exponential parsing time in flow collections leads to denial of service

▾ Twilightjs-yaml · js-yamlvia GHSA
GHSA-gcjh-h69q-9w9gMedium
2mo ago

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag

▾ Sunlitgoogle · github.com/google/cel-govia GHSA
GHSA-r277-6w6q-xmqwCritical· 9.1
2mo ago

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

▾ Midnightgetkin · github.com/getkin/kin-openapivia GHSA
GHSA-mfg7-5gfp-c4w3Medium· 5.3
2mo ago

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

▾ Sunlitnetty · io.netty:netty-codec-dnsvia GHSA
GHSA-v74w-7mr3-4qg3High· 7.5
2mo ago

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

▾ Twilightnetty · io.netty:netty-codec-xmlvia GHSA
CVE-2026-55607High
2mo ago

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.69%via GHSA
CVE-2026-59214High· 7.3
2mo ago

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

▾ Twilightopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59218Medium· 5.3
2mo ago

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

▾ Sunlitopen-webui · open-webuiEPSS 0.41%via GHSA
CVE-2026-59226Low· 3.1
2mo ago

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

▾ Sunlitopen-webui · open-webuiEPSS 0.53%via GHSA
CVE-2026-59220Medium· 6.5
2mo ago

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

▾ Sunlitopen-webui · open-webuiEPSS 0.57%via GHSA
CVE-2026-59227Medium· 4.3
2mo ago

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59715Low· 3.1
2mo ago

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

▾ Sunlitopen-webui · open-webuiEPSS 0.36%via GHSA
CVE-2026-59219High· 7.1
2mo ago

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

▾ Twilightopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-59217Medium· 4.3
2mo ago

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVE-2026-59213Low· 3.5
2mo ago

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVEs tagged “ghsa” — page 65 · VulnSea