Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2024-7708High· 7.5Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
CVE-2026-64641HighNext.js: Denial of Service in App Router using Server Actions
Next.js: Denial of Service in App Router using Server Actions
CVE-2026-64642HighNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
CVE-2026-64643MediumNext.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js: Unauthenticated disclosure of internal Server Function endpoints
CVE-2026-64644MediumNext.js: Denial of Service in the Image Optimization API using SVGs
Next.js: Denial of Service in the Image Optimization API using SVGs
CVE-2026-64645HighNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
CVE-2026-64646MediumNext.js: Unbounded Server Action payload in Edge runtime
Next.js: Unbounded Server Action payload in Edge runtime
CVE-2026-64647MediumNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
GHSA-m7jc-p4hf-xhwqHighDuplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-wq64-hcrf-8m56HighDuplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
GHSA-mwq7-vcmc-cm4qHighDuplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-38fj-36m5-783cMediumDuplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-55554LowDompdf: Chroot Validation Bypass
Dompdf: Chroot Validation Bypass
CVE-2026-55555LowDompdf: File existence oracle via font-face stylesheet declaration
Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-56722MediumDompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
CVE-2026-56821High· 7.4Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
CVE-2026-56822High· 7.4Netty: TOCTOU in OcspServerCertificateValidator
Netty: TOCTOU in OcspServerCertificateValidator
CVE-2026-59898MediumNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-59900MediumNetty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
CVE-2026-59919Medium· 5.5Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-59920Medium· 6.5Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
CVE-2026-59921Medium· 5.7Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-59209Highn8n: Shared Credential Header Leak via HTTP Request Pagination Expression
n8n: Shared Credential Header Leak via HTTP Request Pagination Expression
CVE-2026-59206Highn8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVE-2026-59207Highn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
CVE-2026-59208Highn8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVE-2026-65595Highn8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65591HighPoCn8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-65016Highn8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner