VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-59731High· 8.2
2mo ago

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

▾ Twilightastro · astroEPSS 0.47%via GHSA
CVE-2026-62843Medium· 6.8
2mo ago

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.39%via GHSA
CVE-2026-62685High· 8.1
2mo ago

File Browser: Colliding username normalization gives two users the same home directory

File Browser: Colliding username normalization gives two users the same home directory

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
GHSA-f4gw-2p7v-4548Medium
2mo ago

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

▾ Sunlitaxios · axiosvia GHSA
GHSA-mmx7-hfxf-jppxMedium
2mo ago

Axios: Prototype pollution gadgets can alter axios request construction

Axios: Prototype pollution gadgets can alter axios request construction

▾ Sunlitaxios · axiosvia GHSA
GHSA-jqh4-m9w3-8hp9Medium
2mo ago

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

▾ Sunlitaxios · axiosvia GHSA
GHSA-mwf2-3pr3-8698Medium
2mo ago

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

▾ Sunlitaxios · axiosvia GHSA
GHSA-7q8q-rj6j-mhjqMedium
2mo ago

Axios: Nested axios option objects can consume polluted prototype values

Axios: Nested axios option objects can consume polluted prototype values

▾ Sunlitaxios · axiosvia GHSA
GHSA-hcpx-6fm6-wx23Medium
2mo ago

Axios form serializer maxDepth bypass via {} metatoken

Axios form serializer maxDepth bypass via {} metatoken

▾ Sunlitaxios · axiosvia GHSA
GHSA-gcfj-64vw-6mp9High
2mo ago

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

▾ Twilightaxios · axiosvia GHSA
CVE-2026-53515High· 7.1
2mo ago

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

▾ Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
GHSA-4g3v-8h47-v7g6Medium
2mo ago

Astro: Reflected XSS via unescaped View Transition animation properties

Astro: Reflected XSS via unescaped View Transition animation properties

▾ Sunlitastro · astrovia GHSA
CVE-2026-54560High· 7.6
2mo ago

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

▾ Twilightcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.46%via GHSA
CVE-2026-54562Medium· 6.5
2mo ago

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

▾ Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.40%via GHSA
CVE-2026-55667High· 8.2
2mo ago

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.49%via GHSA
CVE-2026-55668Medium· 6.3
2mo ago

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

▾ Sunlitfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.38%via GHSA
CVE-2026-59870Medium· 5.3
2mo ago

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA

▾ Sunlitjs-yaml · js-yamlEPSS 0.64%via GHSA
CVE-2026-59948High· 7.0
2mo ago

Composer: Arbitrary file write outside vendor via malicious transitive package name

Composer: Arbitrary file write outside vendor via malicious transitive package name

▾ Twilightcomposer · composer/composerEPSS 0.16%via GHSA
GHSA-pmv8-rq9r-6j72Medium
2mo ago

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

▾ Sunlitaxios · axiosvia GHSA
GHSA-xj6q-8x83-jv6gMedium
2mo ago

Axios: Prototype pollution auth subfields can inject Basic auth

Axios: Prototype pollution auth subfields can inject Basic auth

▾ Sunlitaxios · axiosvia GHSA
GHSA-42h9-826w-cgv3Medium
2mo ago

Axios: Excessive recursion in formDataToJSON can cause denial of service

Axios: Excessive recursion in formDataToJSON can cause denial of service

▾ Sunlitaxios · axiosvia GHSA
CVE-2026-16221High· 7.5
2mo ago

fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)

A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrep…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.25%via CSAF
CVE-2026-55177High
2mo ago

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard

▾ Twilighttak-ps · @tak-ps/cloudtakvia GHSA
GHSA-8qqm-fp2q-v734High· 8.2
2mo ago

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies

▾ Twilightzalando · github.com/zalando/skippervia GHSA
GHSA-mfr4-mq8w-vmg6Medium· 6.6
2mo ago

PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs

PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs

▾ Sunlitproot-distro · proot-distrovia GHSA
CVE-2026-53598High· 7.5
2mo ago

Prompty: Arbitrary file read via file reference expansion

Prompty: Arbitrary file read via file reference expansion

▾ Twilightprompty · promptyEPSS 1.3%via GHSA
CVE-2026-53597High
2mo ago

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader

▾ Twilightprompty · @prompty/coreEPSS 0.97%via GHSA
CVE-2026-11400High· 8.0
2mo ago

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightamazon · software.amazon.jdbc:aws-advanced-jdbc-wrapperEPSS 0.30%via GHSA
GHSA-rjwr-m7qx-3fjrLow
2mo ago

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

▾ Sunlitoapi-codegen · github.com/oapi-codegen/oapi-codegen/v2via GHSA
GHSA-cvpc-hccg-wmw4Medium· 6.3
2mo ago

Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration

Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration

▾ Sunlitverbb · verbb/formievia GHSA
CVEs tagged “ghsa” — page 75 · VulnSea