Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-54464Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
CVE-2026-54465Mediumwebsocket-driver: Memory exhaustion in HTTP header parser
websocket-driver: Memory exhaustion in HTTP header parser
CVE-2026-54466Criticalwebsocket-driver: Message corruption via abuse of protocol length headers
websocket-driver: Message corruption via abuse of protocol length headers
CVE-2026-54490Mediumwebsocket-driver: Resource limit bypass via message compression
websocket-driver: Resource limit bypass via message compression
GHSA-7gcf-g7xr-8hxjMediumserde_with: KeyValueMap serialization panics on empty sequence or map entries
serde_with: KeyValueMap serialization panics on empty sequence or map entries
GHSA-r3hx-x5rh-p9vvHighdjango-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
CVE-2026-52883MediumMantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
CVE-2026-62944HighMantisBT: Stored XSS in print_all_bug_page_word.php
MantisBT: Stored XSS in print_all_bug_page_word.php
CVE-2026-50552Medium· 6.3Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
CVE-2026-52847CriticalMantisBT: Reflected XSS in admin/install.php
MantisBT: Reflected XSS in admin/install.php
CVE-2026-52881CriticalMantisBT: Reflected XSS in admin/install.php via unescaped printf
MantisBT: Reflected XSS in admin/install.php via unescaped printf
CVE-2026-52882MediumMantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
CVE-2026-49273HighMantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
CVE-2026-49280MediumMantisBT: REST API unauthorized Issue status change
MantisBT: REST API unauthorized Issue status change
GHSA-8q6q-m837-fv64Medium· 6.4Koel has SSRF through Authenticated Subsonic podcast feed URLs
Koel has SSRF through Authenticated Subsonic podcast feed URLs
CVE-2026-47142HighMantisBT: SQL Injection via history_order Configuration Value
MantisBT: SQL Injection via history_order Configuration Value
CVE-2026-50646High· 7.8.NET Framework Remote Code Execution Vulnerability
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-10051Medium· 5.3jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)
A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintention…
CVE-2026-59889Medium· 6.5com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…
A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
A flaw was found in pyasn1, a Python library for Abstract Syntax Notation One (ASN.1). The BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A remote attacker cou…
CVE-2026-59886High· 7.5pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)
A remote attacker can exploit this by providing specially crafted BER/CER/DER-encoded ASN.1 data with a large exponent in the REAL value. When the application subsequently prints, logs, compares, or performs arithmetic on the decoded value…
CVE-2026-59888Medium· 6.5com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…
A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter…
CVE-2026-50650High· 7.8.NET Framework Elevation of Privilege Vulnerability
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50527High· 7.5.NET Framework Denial of Service Vulnerability
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47303High· 8.8ASP.NET Core Elevation of Privilege Vulnerability
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47300High· 8.8ASP.NET Core Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-50526High· 7.0.NET Tampering Vulnerability
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-56170High· 7.5ASP.NET Core Denial of Service Vulnerability
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-47304High· 8.1.NET Security Feature Bypass Vulnerability
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524High· 7.5.NET Framework Denial of Service Vulnerability
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.