Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…
CVE-2026-53467Medium· 5.3ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
CVE-2026-53666Medium· 6.1React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
CVE-2026-53667Medium· 6.9React Router: RSCErrorHandler Missing Protocol Validation (XSS)
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
CVE-2026-53668Medium· 6.9React Router: Open redirect leading to XSS
React Router: Open redirect leading to XSS
CVE-2026-53669MediumReact Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
CVE-2026-55223Mediumc3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
CVE-2026-54696Low· 3.7Ruby json: JSON generator heap buffer overflow when streaming to an IO
Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59935Highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-7rqj-j65f-68whCriticalAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-xmf8-cvqr-rfgjHigh· 7.5Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-8fpg-xm3f-6cx3CriticalAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
CVE-2026-59931High· 7.7PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
CVE-2026-59932High· 7.5PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVE-2026-59933High· 7.5PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVE-2026-59938Mediumpypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
CVE-2026-64648MediumNext.js: Cache confusion of response bodies for requests with bodies
Next.js: Cache confusion of response bodies for requests with bodies
CVE-2026-64649HighNext.js: Server-Side Request Forgery in Server Actions on custom servers
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-whvh-wf3x-g77jLowJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
GHSA-h5v5-8746-g7mmMediumJupyterLab PluginManager lock-rule enforcement bypass
JupyterLab PluginManager lock-rule enforcement bypass
GHSA-89vp-jrxv-24w8MediumJupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
GHSA-gx64-gj6p-pc4cHighJupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
GHSA-pppj-hq3g-57pjHighJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
GHSA-9cmh-xcqm-5hqrMediumn8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
GHSA-jqwr-vx3p-r266Mediumn8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-652q-gvq3-74qvMediumn8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-fmvg-vhqq-r2mjMediumDuplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data