VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-14257High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)

A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-53467Medium· 5.3
2mo ago

ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged

ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.33%via GHSA
CVE-2026-53666Medium· 6.1
2mo ago

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

▾ Sunlitreact-router · react-routerEPSS 0.42%via GHSA
CVE-2026-53667Medium· 6.9
2mo ago

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

▾ Sunlitreact-router · react-routerEPSS 0.36%via GHSA
CVE-2026-53668Medium· 6.9
2mo ago

React Router: Open redirect leading to XSS

React Router: Open redirect leading to XSS

▾ Sunlitreact-router · react-routerEPSS 0.34%via GHSA
CVE-2026-53669Medium
2mo ago

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

▾ Sunlitreact-router · react-routerEPSS 0.32%via GHSA
CVE-2026-55223Medium
2mo ago

c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets

c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets

▾ Sunlitmchange · com.mchange:c3p0EPSS 0.48%via GHSA
CVE-2026-54696Low· 3.7
2mo ago

Ruby json: JSON generator heap buffer overflow when streaming to an IO

Ruby json: JSON generator heap buffer overflow when streaming to an IO

▾ Sunlitjson · jsonEPSS 0.38%via GHSA
CVE-2026-59936High
2mo ago

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59935High
2mo ago

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
GHSA-x445-f3h2-j279Medium· 6.8
2mo ago

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

▾ Sunlitauth · @auth/corevia GHSA
GHSA-7rqj-j65f-68whCritical
2mo ago

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

▾ Midnightauth · @auth/corevia GHSA
GHSA-xmf8-cvqr-rfgjHigh· 7.5
2mo ago

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

▾ Twilightauth · @auth/corevia GHSA
GHSA-8fpg-xm3f-6cx3Critical
2mo ago

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)

▾ Midnightnext-auth · next-authvia GHSA
CVE-2026-59931High· 7.7
2mo ago

PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.53%via GHSA
CVE-2026-59932High· 7.5
2mo ago

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.70%via GHSA
CVE-2026-59933High· 7.5
2mo ago

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.70%via GHSA
CVE-2026-59938Medium
2mo ago

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-59937Medium
2mo ago

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

▾ Sunlitpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-64648Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies

Next.js: Cache confusion of response bodies for requests with bodies

▾ Sunlitnext · nextEPSS 0.34%via GHSA
CVE-2026-64649High
2mo ago

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Next.js: Server-Side Request Forgery in Server Actions on custom servers

▾ Twilightnext · nextEPSS 0.46%via GHSA
GHSA-whvh-wf3x-g77jLow
2mo ago

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

▾ Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-h5v5-8746-g7mmMedium
2mo ago

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

▾ Sunlitjupyterlab · jupyterlabvia OSV
GHSA-89vp-jrxv-24w8Medium
2mo ago

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

▾ Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-gx64-gj6p-pc4cHigh
2mo ago

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

▾ Twilightjupyterlab · jupyterlabvia GHSA
GHSA-pppj-hq3g-57pjHigh
2mo ago

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

▾ Twilightjupyterlab · jupyterlabvia GHSA
GHSA-9cmh-xcqm-5hqrMedium
2mo ago

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

▾ Sunlitn8n · n8nvia GHSA
GHSA-jqwr-vx3p-r266Medium
2mo ago

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances

▾ Sunlitn8n · n8nvia GHSA
GHSA-652q-gvq3-74qvMedium
2mo ago

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation

▾ Sunlitn8n · n8nvia GHSA
GHSA-fmvg-vhqq-r2mjMedium
2mo ago

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

▾ Sunlitn8n · n8nvia GHSA
CVEs tagged “ghsa” — page 68 · VulnSea