VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-50648High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50528High· 8.2
2mo ago

.NET Security Feature Bypass Vulnerability

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.61%via CVEORG
CVE-2026-50525High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-50659Medium· 6.5
2mo ago

.NET Spoofing Vulnerability

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.74%via CVEORG
CVE-2026-50651High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-59197High· 8.2
2mo ago

Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)

A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.58%via CSAF
CVE-2026-59200High· 7.5
2mo ago

Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59204High· 7.5
2mo ago

Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-57108High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-47302High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-54058Critical· 9.1
2mo ago

Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)

A flaw was found in Pillow prior to 12.3.0. When an uncompressed McIdas AREA image is loaded from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width. Pixel a…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.68%via CSAF
GHSA-hgjx-r89m-m7v4Critical· 9.9
2mo ago

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-54335Low· 3.7
2mo ago

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__

▾ Sunlitfeathersjs · @feathersjs/commonsEPSS 0.39%via GHSA
GHSA-pqg7-v6wh-3pfpHigh· 8.5
2mo ago

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

▾ Twilightalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia GHSA
CVE-2026-54448High
2mo ago

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
GHSA-9hc2-hjx8-q6pvCritical· 9.6
2mo ago

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution

▾ Midnighttidgi · tidgivia GHSA
GHSA-mqxv-9rm6-w8qcHigh
2mo ago

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

▾ Twilightlin-snow · github.com/lin-snow/ech0via GHSA
GHSA-q3v2-xj35-9grxMedium· 4.9
2mo ago

Umbraco.AI discloses sensitive application configuration values

Umbraco.AI discloses sensitive application configuration values

▾ SunlitUmbraco · Umbraco.AIvia GHSA
CVE-2026-55608Medium· 4.2
2mo ago

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode

▾ Sunlitn8n-mcp · n8n-mcpEPSS 0.28%via GHSA
GHSA-7rx3-5wx3-5v76High· 7.7
2mo ago

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

▾ Twilightforgekeep · github.com/forgekeep/nebula-meshvia GHSA
CVE-2026-50141High
2mo ago

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v3EPSS 0.43%via GHSA
CVE-2026-54052Critical· 9.9
2mo ago

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

▾ Midnightn8n-mcp · n8n-mcpEPSS 0.39%via GHSA
CVE-2026-54250Medium· 5.8
2mo ago

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression

▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.17%via GHSA
CVE-2026-50131High· 8.6PoC
2mo ago

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

▾ Midnightfedify · @fedify/fedifyEPSS 0.42%via GHSA
CVE-2026-45262Critical· 9.9
2mo ago

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-45693High· 7.5
2mo ago

FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents

▾ Twilightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-45263High· 8.0
2mo ago

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export

▾ Twilightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-45710Low· 3.5
2mo ago

FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`

FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`

▾ Sunlitfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-49477High· 7.5
2mo ago

soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings (CVE-2026-49477)

A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expressi…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-49978High· 8.1
2mo ago

dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)

A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM eleme…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.40%via CSAF
CVEs tagged “ghsa” — page 78 · VulnSea