VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-8342-988q-86crHigh
2mo ago

n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

▾ Twilightn8n · n8nvia GHSA
GHSA-64xh-79j6-r5v8High
2mo ago

n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes

▾ Twilightn8n · n8nvia GHSA
GHSA-w46p-w7w2-fr9gHigh
2mo ago

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool

▾ Twilightn8n · n8nvia GHSA
GHSA-h5xr-fqvj-253pHigh
2mo ago

Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`

Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`

▾ Twilightn8n · n8nvia GHSA
GHSA-vhcw-f978-xjjgHigh
2mo ago

Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

▾ Twilightn8n · n8nvia GHSA
GHSA-725q-c4vp-q4cgHigh
2mo ago

Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

▾ Twilightn8n · n8nvia GHSA
GHSA-mhvh-gwhr-76pwMedium
2mo ago

Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header

Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-65015High
2mo ago

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool

▾ Twilightn8n · n8nEPSS 0.61%via GHSA
CVE-2026-65598High
2mo ago

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

▾ Twilightn8n · n8nEPSS 0.34%via GHSA
CVE-2026-65597High
2mo ago

n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

▾ Twilightn8n · n8nEPSS 0.30%via GHSA
CVE-2026-65592High
2mo ago

n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`

n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`

▾ Twilightn8n · n8nEPSS 0.24%via GHSA
CVE-2026-65599Medium
2mo ago

n8n: Google Service Account Private Key Exposed in JWT Header

n8n: Google Service Account Private Key Exposed in JWT Header

▾ Sunlitn8n · n8nEPSS 0.25%via GHSA
CVE-2026-56819High· 7.5PoC
2mo ago

io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819)

A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompress…

▾ MidnightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.66%via CSAF
CVE-2026-55851High· 7.5
2mo ago

io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851)

A flaw was found in Netty's codec-haproxy module. A remote attacker could exploit a vulnerability in the HAProxyMessageDecoder by sending a specially crafted PROXY protocol v2 message. This leads to unbounded buffer accumulation, causing a…

▾ TwilightRed Hat · OpenShift ServerlessEPSS 0.63%via CSAF
CVE-2026-56745High· 7.5
2mo ago

netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745)

A flaw was found in Netty. A remote attacker can exploit a vulnerability in the `SpdyHttpDecoder` handler of Netty's SPDY-to-HTTP codec. When processing a client-initiated `SYN_STREAM` frame, the decoder fails to release allocated memory i…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.63%via CSAF
CVE-2026-56746High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)

A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.41%via CSAF
CVE-2026-56816High· 7.5
2mo ago

io.netty:netty-codec-http3: Netty: Denial of Service due to uncontrolled memory buffering in HTTP/3 (CVE-2026-56816)

A flaw was found in Netty. An unauthenticated remote attacker can exploit a vulnerability in Netty's `Http3FrameCodec` by sending specially crafted HTTP/3 reserved frames with excessive payload lengths. This can lead to uncontrolled memory…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.64%via CSAF
CVE-2026-56817High· 7.5
2mo ago

io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability (CVE-2026-56817)

A flaw was found in Netty, a network application framework. A remote attacker could exploit this vulnerability by sending specially crafted XML data containing a DOCTYPE declaration to a vulnerable XmlDecoder within the Netty channel pipel…

▾ TwilightRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.69%via CSAF
CVE-2026-56820High· 7.4
2mo ago

io.netty/netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820)

A flaw was found in Netty. The `OcspClient` component fails to validate that the Certificate ID in an Online Certificate Status Protocol (OCSP) response matches the requested Certificate ID. This vulnerability allows a remote attacker to b…

▾ TwilightRed Hat · Red Hat Data Grid 8.6.3EPSS 0.31%via CSAF
CVE-2026-59765Medium· 7.5
2mo ago

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.50%via GHSA
CVE-2026-58429Medium· 4.9
2mo ago

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
GHSA-r7wm-3cxj-wff9High
2mo ago

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)

▾ Twilightfasterxml · com.fasterxml.jackson.core:jackson-corevia GHSA
GHSA-2rp8-mm9q-fp49Medium· 5.7
2mo ago

TypeORM: migration:generate template-literal code injection

TypeORM: migration:generate template-literal code injection

▾ Sunlittypeorm · typeormvia GHSA
GHSA-9wjq-cp2p-hrgfMedium· 4.7
2mo ago

Loofah: SVG `href` attribute bypasses local-reference restriction

Loofah: SVG `href` attribute bypasses local-reference restriction

▾ Sunlitloofah · loofahvia GHSA
GHSA-5qhf-9phg-95m2Low
2mo ago

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons

▾ Sunlitloofah · loofahvia GHSA
GHSA-hrxh-6v49-42gfHigh
2mo ago

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

▾ Twilightgrpc · google.golang.org/grpcvia GHSA
GHSA-9mqv-5hh9-4cggMedium· 5.3
2mo ago

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

▾ Sunlithono · @hono/node-servervia GHSA
GHSA-cj75-f6xr-r4g7Medium
2mo ago

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

▾ Sunlitrails-html-sanitizer · rails-html-sanitizervia GHSA
GHSA-rwj8-pgh3-r573High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-8r6m-32jq-jx6qHigh
2mo ago

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits

▾ Twilightfast-xml-parser · fast-xml-parservia GHSA
CVEs tagged “ghsa” — page 71 · VulnSea