Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-r292-9mhp-454mMedium· 5.3node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
GHSA-qvxh-prvr-85w2Low· 3.7ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
ImageMagick: Use-After-Free in FormatMagickCaption when memory allocation fails
GHSA-hwf3-r46v-5ggxLow· 2.9ImageMagick: Information Disclosure when printing profiles with debug enabled
ImageMagick: Information Disclosure when printing profiles with debug enabled
GHSA-6vxp-gfwf-hcr9Low· 2.9ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
GHSA-7c7m-fpjw-gwcqLow· 2.9ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
GHSA-j8rh-v2r8-v94xLow· 2.9ImageMagick: Memory Leak in hough lines operation when an operation fails
ImageMagick: Memory Leak in hough lines operation when an operation fails
GHSA-99w9-hv66-rfv7Low· 2.9ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
GHSA-jfq9-q63x-rc63Low· 2.9ImageMagick: Memory Leak in TIFF encoder when an allocation fails
ImageMagick: Memory Leak in TIFF encoder when an allocation fails
GHSA-h7f2-f9cc-h2gvLow· 3.7ImageMagick: Memory Leak in YUV decoder when opening of blob fails
ImageMagick: Memory Leak in YUV decoder when opening of blob fails
GHSA-r628-69v2-2f9cLow· 2.9ImageMagick: Memory Leak in MIFF encoder when allocaton fails
ImageMagick: Memory Leak in MIFF encoder when allocaton fails
GHSA-m596-67p7-69whLow· 2.9ImageMagick: Memory leak in VIFF encoder when allocation fails
ImageMagick: Memory leak in VIFF encoder when allocation fails
GHSA-h58x-r7f7-rh84Low· 3.7ImageMagick: Memory Leak in ICON decoder when allocation fails
ImageMagick: Memory Leak in ICON decoder when allocation fails
GHSA-h5r4-w88w-7ccrLow· 2.5ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
CVE-2026-54672High· 7.8electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
CVE-2026-54673Highelectron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
CVE-2026-55510Medium· 5.5ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
CVE-2026-55575HighLiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
CVE-2026-55594Medium· 5.3ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
CVE-2026-55595Medium· 4.7ImageMagick: Infinite Loop in connected-components when providing invalid arguments
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
CVE-2026-55597Medium· 5.5ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
CVE-2026-55628Medium· 6.1ImageMagick: Policy Bypass in concatenate operation due to missing checks
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-4w2j-m93h-cj5jHigh· 7.5Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-rvhp-75f6-9jqhLow· 3.3ImageMagick: Policy Bypass possible with matrix-backed operations
ImageMagick: Policy Bypass possible with matrix-backed operations
GHSA-56m6-8q75-f2rwMedium· 4.7ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-hc76-7mpc-qjqhMedium· 5.7ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-qh5g-q395-cx4jLow· 3.7ImageMagick: Heap-use-after-free via XMP profile could result in a crash
ImageMagick: Heap-use-after-free via XMP profile could result in a crash
GHSA-v3j6-27vc-7pw2Low· 3.3ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check
GHSA-vghg-5jrg-2398Low· 3.3ImageMagick: Policy Bypass in script operation due to missing checks
ImageMagick: Policy Bypass in script operation due to missing checks
GHSA-6jwg-7q3p-5fqmLow· 3.7ImageMagick: Use-After-Free when freetype initialization fails
ImageMagick: Use-After-Free when freetype initialization fails
GHSA-pp9r-ppc4-25w4High· 8.8Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation