Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-59731High· 8.2Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
CVE-2026-62843Medium· 6.8File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVE-2026-62685High· 8.1File Browser: Colliding username normalization gives two users the same home directory
File Browser: Colliding username normalization gives two users the same home directory
GHSA-f4gw-2p7v-4548MediumAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
GHSA-mmx7-hfxf-jppxMediumAxios: Prototype pollution gadgets can alter axios request construction
Axios: Prototype pollution gadgets can alter axios request construction
GHSA-jqh4-m9w3-8hp9MediumAxios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
GHSA-mwf2-3pr3-8698MediumAxios: HTTP/2 streamed uploads bypass `maxBodyLength`
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
GHSA-7q8q-rj6j-mhjqMediumAxios: Nested axios option objects can consume polluted prototype values
Axios: Nested axios option objects can consume polluted prototype values
GHSA-hcpx-6fm6-wx23MediumAxios form serializer maxDepth bypass via {} metatoken
Axios form serializer maxDepth bypass via {} metatoken
GHSA-gcfj-64vw-6mp9HighAxios Node HTTP adapter can use an inherited proxy after interceptor config cloning
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
CVE-2026-53515High· 7.1@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
GHSA-4g3v-8h47-v7g6MediumAstro: Reflected XSS via unescaped View Transition animation properties
Astro: Reflected XSS via unescaped View Transition animation properties
CVE-2026-54560High· 7.6Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
CVE-2026-54562Medium· 6.5Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
CVE-2026-55667High· 8.2File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVE-2026-55668Medium· 6.3File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVE-2026-59870Medium· 5.3js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
js-yaml: Quadratic-complexity (O(n^2)) DoS via !!omap tag in YAML11_SCHEMA
CVE-2026-59948High· 7.0Composer: Arbitrary file write outside vendor via malicious transitive package name
Composer: Arbitrary file write outside vendor via malicious transitive package name
GHSA-pmv8-rq9r-6j72MediumAxios: Deep formToJSON Key Recursion Can Cause Denial of Service
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
GHSA-xj6q-8x83-jv6gMediumAxios: Prototype pollution auth subfields can inject Basic auth
Axios: Prototype pollution auth subfields can inject Basic auth
GHSA-42h9-826w-cgv3MediumAxios: Excessive recursion in formDataToJSON can cause denial of service
Axios: Excessive recursion in formDataToJSON can cause denial of service
CVE-2026-16221High· 7.5fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)
A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrep…
CVE-2026-55177HighCloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard
GHSA-8qqm-fp2q-v734High· 8.2Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
Skipper: Incomplete fix for CVE-2026-50197: an oversized body can bypass OPA deny-on-presence Rego policies
GHSA-mfr4-mq8w-vmg6Medium· 6.6PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs
PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs
CVE-2026-53598High· 7.5Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
CVE-2026-53597HighPrompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
CVE-2026-11400High· 8.0AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
GHSA-rjwr-m7qx-3fjrLowoapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
GHSA-cvpc-hccg-wmw4Medium· 6.3Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration