VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2024-7708High· 7.5
2mo ago

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

▾ Twilighteclipse · org.eclipse.jetty:jetty-serverEPSS 0.44%via GHSA
CVE-2026-64641High
2mo ago

Next.js: Denial of Service in App Router using Server Actions

Next.js: Denial of Service in App Router using Server Actions

▾ Twilightnext · nextEPSS 0.86%via GHSA
CVE-2026-64642High
2mo ago

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale

▾ Twilightnext · nextEPSS 0.64%via GHSA
CVE-2026-64643Medium
2mo ago

Next.js: Unauthenticated disclosure of internal Server Function endpoints

Next.js: Unauthenticated disclosure of internal Server Function endpoints

▾ Sunlitnext · nextEPSS 0.51%via GHSA
CVE-2026-64644Medium
2mo ago

Next.js: Denial of Service in the Image Optimization API using SVGs

Next.js: Denial of Service in the Image Optimization API using SVGs

▾ Sunlitnext · nextEPSS 0.67%via GHSA
CVE-2026-64645High
2mo ago

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

▾ Twilightnext · nextEPSS 0.41%via GHSA
CVE-2026-64646Medium
2mo ago

Next.js: Unbounded Server Action payload in Edge runtime

Next.js: Unbounded Server Action payload in Edge runtime

▾ Sunlitnext · nextEPSS 0.52%via GHSA
CVE-2026-64647Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

▾ Sunlitnext · nextEPSS 0.32%via GHSA
GHSA-m7jc-p4hf-xhwqHigh
2mo ago

Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

▾ Twilightn8n · n8nvia GHSA
GHSA-wq64-hcrf-8m56High
2mo ago

Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

▾ Twilightn8n · n8nvia GHSA
GHSA-mwq7-vcmc-cm4qHigh
2mo ago

Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

▾ Twilightn8n · n8nvia GHSA
GHSA-38fj-36m5-783cMedium
2mo ago

Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-55554Low
2mo ago

Dompdf: Chroot Validation Bypass

Dompdf: Chroot Validation Bypass

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
CVE-2026-55555Low
2mo ago

Dompdf: File existence oracle via font-face stylesheet declaration

Dompdf: File existence oracle via font-face stylesheet declaration

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.51%via GHSA
CVE-2026-56722Medium
2mo ago

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
CVE-2026-56821High· 7.4
2mo ago

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.22%via GHSA
CVE-2026-56822High· 7.4
2mo ago

Netty: TOCTOU in OcspServerCertificateValidator

Netty: TOCTOU in OcspServerCertificateValidator

▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.17%via GHSA
CVE-2026-59898Medium
2mo ago

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.44%via GHSA
CVE-2026-59900Medium
2mo ago

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

▾ Sunlitnetty · io.netty:netty-codec-http2EPSS 0.40%via GHSA
CVE-2026-59919Medium· 5.5
2mo ago

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

▾ Sunlitnetty · io.netty:netty-codec-haproxyEPSS 0.17%via GHSA
CVE-2026-59920Medium· 6.5
2mo ago

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

▾ Sunlitnetty · io.netty:netty-codec-stompEPSS 0.41%via GHSA
CVE-2026-59921Medium· 5.7
2mo ago

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.46%via GHSA
CVE-2026-59209High
2mo ago

n8n: Shared Credential Header Leak via HTTP Request Pagination Expression

n8n: Shared Credential Header Leak via HTTP Request Pagination Expression

▾ Twilightn8n · n8nEPSS 0.40%via GHSA
CVE-2026-59206High
2mo ago

n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration

n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration

▾ Twilightn8n · n8nEPSS 0.66%via GHSA
CVE-2026-59207High
2mo ago

n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector

n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector

▾ Twilightn8n · n8nEPSS 0.45%via GHSA
CVE-2026-59208High
2mo ago

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution

▾ Twilightn8n · n8nEPSS 0.27%via GHSA
CVE-2026-65595High
2mo ago

n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs

▾ Twilightn8n · n8nEPSS 0.69%via GHSA
CVE-2026-65593Medium
2mo ago

n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

▾ Sunlitn8n · n8nEPSS 0.24%via GHSA
CVE-2026-65591HighPoC
2mo ago

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

▾ Midnightn8n · n8nEPSS 0.69%via GHSA
CVE-2026-65016High
2mo ago

n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

▾ Twilightn8n · n8nEPSS 0.45%via GHSA
CVEs tagged “ghsa” — page 70 · VulnSea