VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-49855High· 7.5
2mo ago

tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)

A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.61%via CSAF
CVE-2026-49853High· 7.7
2mo ago

tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)

A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.45%via CSAF
CVE-2026-48801High· 7.5
2mo ago

linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)

A flaw was found in linkify-it, a library for recognizing links with full Unicode support. The LinkifyIt.prototype.match function, the package's primary public API, has an algorithmic complexity of O(N²) for inputs containing many fuzzy li…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.52%via CSAF
CVE-2026-47677Critical
2mo ago

FacturaScripts: Account takeover of any 2FA-enabled user

FacturaScripts: Account takeover of any 2FA-enabled user

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
GHSA-xf7x-x43h-rpqhHigh· 7.5
2mo ago

json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS

json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS

▾ Twilightjson-repair · json-repairvia GHSA
GHSA-8f6j-263m-g72xMedium
2mo ago

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

Apple App Store Server Python Library: SignedDataVerifier accepts stale OCSP GOOD responses and can bypass certificate revocation checks

▾ Sunlitapp-store-server-library · app-store-server-libraryvia GHSA
CVE-2026-59955High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via raw config file appId parsing

Apollo ConfigService access key authentication bypass via raw config file appId parsing

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
GHSA-7xw9-549r-8jrcHigh· 8.5
2mo ago

DIRAC: SQL injection and lack of access control in PilotManager service

DIRAC: SQL injection and lack of access control in PilotManager service

▾ TwilightDIRAC · DIRACvia GHSA
CVE-2026-54064High· 8.7
2mo ago

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-54065High· 8.7
2mo ago

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-55372High· 7.2
2mo ago

NukeViet: Pre-authentication SSRF via X-Forwarded-Host

NukeViet: Pre-authentication SSRF via X-Forwarded-Host

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-59954High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2024-27091Medium· 6.1
2mo ago

GeoNode: Stored XSS to full account takeover

GeoNode: Stored XSS to full account takeover

▾ Sunlitgeonode · geonodeEPSS 0.38%via GHSA
CVE-2025-32781Medium· 6.5
2mo ago

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA
CVE-2026-48118High· 8.2
2mo ago

NukeViet: Unauthenticated Reflected XSS in Comment Module

NukeViet: Unauthenticated Reflected XSS in Comment Module

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-49259High· 8.7
2mo ago

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

▾ Twilightnukeviet · nukeviet/nukevietvia GHSA
CVE-2026-59162High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
CVE-2026-59161High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a smal…

▾ Twilightexcelize · excelizeEPSS 0.66%via NVD
CVE-2026-59193Medium· 4.9
2mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…

▾ Sunlitgetgrav · gravEPSS 0.60%via NVD
GHSA-g936-7jqj-mwv8Critical· 9.0
2mo ago

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation

▾ Midnightalmeidapaulopt · github.com/almeidapaulopt/tsdproxyvia GHSA
CVE-2026-54159Critical· 10.0
2mo ago

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

▾ Midnightprestashop · prestashop/ps_facetedsearchEPSS 0.75%via GHSA
CVE-2026-50551Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.78%via GHSA
CVE-2026-54163Medium· 4.7
2mo ago

Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input

Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input

▾ Sunlitsecure_headers · secure_headersEPSS 0.29%via GHSA
GHSA-h4g2-xfmw-q2c9High
2mo ago

Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset

Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset

▾ Twilightclauster · claustervia GHSA
CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-54063High· 7.5
2mo ago

Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)

Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)

▾ Twilightxuri · github.com/xuri/excelize/v2EPSS 0.61%via GHSA
GHSA-9mqm-qcwf-5qhgMedium· 5.5
2mo ago

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

▾ Sunlitcredsweeper · credsweepervia GHSA
CVE-2026-54068Medium· 5.9
2mo ago

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via GHSA
CVE-2026-54069CriticalPoC
2mo ago

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.58%via GHSA
CVEs tagged “ghsa” — page 79 · VulnSea