Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery
File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-54070High· 7.1SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
GHSA-99j7-fhr2-xfj4Critical`exploration` was removed from crates.io for malicious code
`exploration` was removed from crates.io for malicious code
CVE-2026-54088CriticalPoCFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
CVE-2026-54071High· 7.8BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
GHSA-qv4m-m73m-8hj7High· 8.8NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
GHSA-xrmc-c5cg-rv7xHigh· 8.8SafeInstall agent guard shell parsing can miss raw package execution
SafeInstall agent guard shell parsing can miss raw package execution
GHSA-wm45-qh3g-v83fHigh· 7.7mcp-atlassian: Arbitrary server-side file read via attachment upload
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-g5r6-gv6m-f5jvHigh· 7.7mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
CVE-2026-54158Critical· 9.9SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
GHSA-489g-7rxv-6c8qMedium· 6.5MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
CVE-2026-49866High· 7.5libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2026-49977Medium· 4.3tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-49858Medium· 5.9API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
CVE-2026-5078Medium· 5.3morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVE-2026-59899High· 7.5io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899)
A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. The HTTP decoder in netty-codec-http fails to properly limit the decompression of this content, causing t…
CVE-2026-59901High· 7.5io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) (CVE-2026-59901)
A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data …
CVE-2026-48861Lowmint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`
CVE-2026-49753Mediummint: Content-Length header accepts non-RFC "+" sign prefix
mint: Content-Length header accepts non-RFC "+" sign prefix
CVE-2026-49754Highmint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)
CVE-2026-48862Highmint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS
CVE-2026-55252MediumOpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
CVE-2026-49851High· 7.5Mistune: Potential DoS via quadratic-time parsing in parse_link_text
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVE-2026-52778Critical· 9.8YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
CVE-2026-54651Mediumpypdf: Possible infinite loop when processing threads/articles in writer
pypdf: Possible infinite loop when processing threads/articles in writer
GHSA-387m-935m-c4vwHigh· 7.5Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
GHSA-q6gh-6v2r-hjv3Medium· 6.8Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
GHSA-52vm-mxx8-f227High· 7.7Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
CVE-2026-49476High· 7.5Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
CVE-2026-49485High· 7.5org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint