Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-8342-988q-86crHighn8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-64xh-79j6-r5v8Highn8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-w46p-w7w2-fr9gHighDuplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
GHSA-h5xr-fqvj-253pHighDuplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
GHSA-vhcw-f978-xjjgHighDuplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GHSA-725q-c4vp-q4cgHighDuplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
GHSA-mhvh-gwhr-76pwMediumDuplicate Advisory: Google Service Account Private Key Exposed in JWT Header
Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header
CVE-2026-65015Highn8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
CVE-2026-65598Highn8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
CVE-2026-65597Highn8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
CVE-2026-65592Highn8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
CVE-2026-65599Mediumn8n: Google Service Account Private Key Exposed in JWT Header
n8n: Google Service Account Private Key Exposed in JWT Header
CVE-2026-56819High· 7.5PoCio.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)
A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompress…
CVE-2026-55851High· 7.5io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)
A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…
CVE-2026-56745High· 7.5netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745)
A flaw was found in Netty. A remote attacker can exploit a vulnerability in the `SpdyHttpDecoder` handler of Netty's SPDY-to-HTTP codec. When processing a client-initiated `SYN_STREAM` frame, the decoder fails to release allocated memory i…
CVE-2026-56746High· 7.5io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)
A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…
CVE-2026-56816High· 7.5io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)
A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…
CVE-2026-56817High· 7.5io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability (CVE-2026-56817)
A flaw was found in Netty, a network application framework. A remote attacker could exploit this vulnerability by sending specially crafted XML data containing a DOCTYPE declaration to a vulnerable XmlDecoder within the Netty channel pipel…
CVE-2026-56820High· 7.4io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820)
A flaw was found in Netty. The `OcspClient` component fails to validate that the Certificate ID in an Online Certificate Status Protocol (OCSP) response matches the requested Certificate ID. This vulnerability allows a remote attacker to b…
CVE-2026-59765Medium· 7.5Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-58429Medium· 4.9Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
GHSA-r7wm-3cxj-wff9Highjackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
GHSA-2rp8-mm9q-fp49Medium· 5.7TypeORM: migration:generate template-literal code injection
TypeORM: migration:generate template-literal code injection
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
GHSA-hrxh-6v49-42gfHighgRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-9mqv-5hh9-4cggMedium· 5.3Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
GHSA-cj75-f6xr-r4g7MediumRails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-rwj8-pgh3-r573High· 7.5GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-8r6m-32jq-jx6qHighfast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits