Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-49855High· 7.5tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)
A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…
CVE-2026-49853High· 7.7tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…
CVE-2026-48801High· 7.5linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)
A flaw was found in linkify-it, a library for recognizing links with full Unicode support. The LinkifyIt.prototype.match function, the package's primary public API, has an algorithmic complexity of O(N²) for inputs containing many fuzzy li…
CVE-2026-47677CriticalFacturaScripts: Account takeover of any 2FA-enabled user
FacturaScripts: Account takeover of any 2FA-enabled user
GHSA-xf7x-x43h-rpqhHigh· 7.5json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
GHSA-8f6j-263m-g72xMediumApple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks
CVE-2026-59955High· 7.5Apollo ConfigService access key authentication bypass via raw config file appId parsing
Apollo ConfigService access key authentication bypass via raw config file appId parsing
GHSA-7xw9-549r-8jrcHigh· 8.5DIRAC: SQL injection and lack of access control in PilotManager service
DIRAC: SQL injection and lack of access control in PilotManager service
CVE-2026-54064High· 8.7NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
CVE-2026-54065High· 8.7NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
CVE-2026-55372High· 7.2NukeViet: Pre-authentication SSRF via X-Forwarded-Host
NukeViet: Pre-authentication SSRF via X-Forwarded-Host
CVE-2026-59954High· 7.5Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
CVE-2024-27091Medium· 6.1GeoNode: Stored XSS to full account takeover
GeoNode: Stored XSS to full account takeover
CVE-2025-32781Medium· 6.5Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
CVE-2026-48118High· 8.2NukeViet: Unauthenticated Reflected XSS in Comment Module
NukeViet: Unauthenticated Reflected XSS in Comment Module
CVE-2026-49259High· 8.7NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-59162High· 7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…
CVE-2026-59161High· 7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…
CVE-2026-59193Medium· 4.9Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…
GHSA-g936-7jqj-mwv8Critical· 9.0TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
CVE-2026-54159Critical· 10.0prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
CVE-2026-50551Critical· 9.9SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
CVE-2026-54163Medium· 4.7Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
GHSA-h4g2-xfmw-q2c9HighClauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
CVE-2026-54066High· 7.5PoCSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
CVE-2026-54067Critical· 9.9SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-54063High· 7.5Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
GHSA-9mqm-qcwf-5qhgMedium· 5.5CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
CVE-2026-54068Medium· 5.9SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
CVE-2026-54069CriticalPoCSiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist