VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-54464Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
CVE-2026-54465Medium
2mo ago

websocket-driver: Memory exhaustion in HTTP header parser

websocket-driver: Memory exhaustion in HTTP header parser

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.49%via GHSA
CVE-2026-54466Critical
2mo ago

websocket-driver: Message corruption via abuse of protocol length headers

websocket-driver: Message corruption via abuse of protocol length headers

▾ Midnightwebsocket-driver · websocket-driverEPSS 0.38%via GHSA
CVE-2026-54490Medium
2mo ago

websocket-driver: Resource limit bypass via message compression

websocket-driver: Resource limit bypass via message compression

▾ Sunlitwebsocket-driver · websocket-driverEPSS 0.45%via GHSA
GHSA-7gcf-g7xr-8hxjMedium
2mo ago

serde_with: KeyValueMap serialization panics on empty sequence or map entries

serde_with: KeyValueMap serialization panics on empty sequence or map entries

▾ Sunlitserde_with · serde_withvia GHSA
GHSA-r3hx-x5rh-p9vvHigh
2mo ago

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

▾ Twilightdjango-haystack · django-haystackvia GHSA
CVE-2026-52883Medium
2mo ago

MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs

MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-62944High
2mo ago

MantisBT: Stored XSS in print_all_bug_page_word.php

MantisBT: Stored XSS in print_all_bug_page_word.php

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-50552Medium· 6.3
2mo ago

Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail

Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail

▾ Sunlitphanan · phanan/koelEPSS 0.27%via GHSA
CVE-2026-52847Critical
2mo ago

MantisBT: Reflected XSS in admin/install.php

MantisBT: Reflected XSS in admin/install.php

▾ Midnightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-52881Critical
2mo ago

MantisBT: Reflected XSS in admin/install.php via unescaped printf

MantisBT: Reflected XSS in admin/install.php via unescaped printf

▾ Midnightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-52882Medium
2mo ago

MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-49273High
2mo ago

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-49280Medium
2mo ago

MantisBT: REST API unauthorized Issue status change

MantisBT: REST API unauthorized Issue status change

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
GHSA-8q6q-m837-fv64Medium· 6.4
2mo ago

Koel has SSRF through Authenticated Subsonic podcast feed URLs

Koel has SSRF through Authenticated Subsonic podcast feed URLs

▾ Sunlitphanan · phanan/koelvia GHSA
CVE-2026-47142High
2mo ago

MantisBT: SQL Injection via history_order Configuration Value

MantisBT: SQL Injection via history_order Configuration Value

▾ Twilightmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-50646High· 7.8
2mo ago

.NET Framework Remote Code Execution Vulnerability

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 4.0%via CVEORG
CVE-2026-10051Medium· 5.3
2mo ago

jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)

A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintention…

▾ SunlitRed Hat · Red Hat Satellite 6.17 for RHEL 9EPSS 0.30%via CSAF
CVE-2026-59889Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…

A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…

▾ SunlitRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.39%via CSAF
CVE-2026-59885High· 7.5
2mo ago

pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)

A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.62%via CSAF
CVE-2026-59886High· 7.5
2mo ago

pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)

A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.62%via CSAF
CVE-2026-59888Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…

A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-50650High· 7.8
2mo ago

.NET Framework Elevation of Privilege Vulnerability

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · .NET 8.0EPSS 0.46%via CVEORG
CVE-2026-50527High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-47303High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-47300High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.78%via CVEORG
CVE-2026-50526High· 7.0
2mo ago

.NET Tampering Vulnerability

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.22%via CVEORG
CVE-2026-56170High· 7.5
2mo ago

ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-47304High· 8.1
2mo ago

.NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-50524High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVEs tagged “ghsa” — page 77 · VulnSea