Tagged “ghsa”
CVEs tagged ghsa, newest first.
3811 CVEsRSS
CVE-2026-61629High· 7.5PoCnginx ignition is a user interface for the nginx web server
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptL…
CVE-2026-61630Medium· 4.2nginx ignition is a user interface for the nginx web server
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the is…
CVE-2026-55074High· 8.2Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec
Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and r…
CVE-2026-55071High· 8.4PoCMCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…
CVE-2026-61670Medium· 6.5microsandbox is an easy, fast, local-first microVM runtime and library
microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repea…
CVE-2026-77528Medium· 5.3Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio
Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the com…
GHSA-xwmw-prc4-v3crHigh· 8.8Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
GHSA-pr6h-vr44-xq8jMedium· 5.3Obot: MCP Registry API readable without authentication
Obot: MCP Registry API readable without authentication
GHSA-jgh3-fggc-mcpmHigh· 7.6Obot: Server-Side Request Forgery via remote MCP server URL
Obot: Server-Side Request Forgery via remote MCP server URL
CVE-2026-59163Critical· 9.1PoCMnemosyne is a memory layer for artificial intelligence agents
Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…
CVE-2026-85058High· 7.5PoCMoquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths…
CVE-2026-71537Medium· 6.5Paymenter is a free and open-source webshop solution for management of hosting services
Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…
GHSA-jr78-w6w5-m8f8High· 7.3Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
GHSA-9rcc-pmj8-ffhrMedium· 6.1Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
CVE-2025-66455Critical· 9.8LMDeploy is a toolkit for compressing, deploying, and serving large language models
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…
GHSA-39wr-7q6h-cf68High· 7.5LMDeploy has an SSRF bypass
LMDeploy has an SSRF bypass
CVE-2026-33625High· 8.8PoCLMDeploy is a toolkit for compressing, deploying, and serving large language models
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…
CVE-2026-64847Medium· 6.8AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…
CVE-2026-91127High· 8.2File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications
File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…
CVE-2026-84992Medium· 6.1PoCmd-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript
md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …
CVE-2026-63458High· 7.1Perses is an open-source dashboard and visualization project for observability data
Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…
CVE-2026-63445High· 7.1Perses is an open-source dashboard and visualization project for observability data
Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…
CVE-2026-63199High· 8.3Perses is an open-source dashboard and visualization project for observability data
Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…
CVE-2026-77616Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…
CVE-2026-77610Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…
CVE-2026-77609Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…
CVE-2026-77607Medium· 6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…
CVE-2026-63406Medium· 5.9PoCAnyCable is a realtime server for reliable two-way communication that supports any backend
AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…
CVE-2026-63405Medium· 5.9PoCAnyCable is a realtime server for reliable two-way communication that supports any backend
AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…
CVE-2026-63349High· 7.0⚖ disputedAnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…