VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-54089Critical· 9.1
2mo ago

File Browser: Authentication Bypass via Proxy Auth Header Forgery

File Browser: Authentication Bypass via Proxy Auth Header Forgery

▾ Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.61%via GHSA
CVE-2026-54070High· 7.1
2mo ago

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

SiYuan: Stored XSS in Bazaar marketplace via package README event handlers

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.30%via GHSA
GHSA-99j7-fhr2-xfj4Critical
2mo ago

`exploration` was removed from crates.io for malicious code

`exploration` was removed from crates.io for malicious code

▾ Midnightexploration · explorationvia GHSA
CVE-2026-54088CriticalPoC
2mo ago

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

▾ Abyssalfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.76%via GHSA
CVE-2026-54071High· 7.8
2mo ago

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

▾ TwilightBabelDOC · BabelDOCEPSS 0.38%via GHSA
GHSA-qv4m-m73m-8hj7High· 8.8
2mo ago

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

▾ Twilightnotrinos · notrinos/notrinos-erpvia GHSA
GHSA-xrmc-c5cg-rv7xHigh· 8.8
2mo ago

SafeInstall agent guard shell parsing can miss raw package execution

SafeInstall agent guard shell parsing can miss raw package execution

▾ Twilightsafeinstall-cli · safeinstall-clivia GHSA
GHSA-wm45-qh3g-v83fHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary server-side file read via attachment upload

mcp-atlassian: Arbitrary server-side file read via attachment upload

▾ Twilightmcp-atlassian · mcp-atlassianvia OSV
GHSA-g5r6-gv6m-f5jvHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

▾ Twilightmcp-atlassian · mcp-atlassianvia GHSA
CVE-2026-54158Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
GHSA-489g-7rxv-6c8qMedium· 6.5
2mo ago

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

▾ Sunlitmcp-atlassian · mcp-atlassianvia OSV
CVE-2026-49866High· 7.5
2mo ago

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

▾ Twilightlibp2p · @libp2p/gossipsubEPSS 0.63%via GHSA
CVE-2026-49977Medium· 4.3
2mo ago

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

▾ Sunlittarteaucitronjs · tarteaucitronjsEPSS 0.35%via GHSA
CVE-2026-49858Medium· 5.9
2mo ago

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

▾ Sunlitapi-platform · api-platform/coreEPSS 0.32%via GHSA
CVE-2026-5078Medium· 5.3
2mo ago

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

▾ Sunlitmorgan · morganEPSS 0.41%via GHSA
CVE-2026-59899High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899)

A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. The HTTP decoder in netty-codec-http fails to properly limit the decompression of this content, causing t…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.61%via CSAF
CVE-2026-59901High· 7.5
2mo ago

io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) (CVE-2026-59901)

A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data …

▾ TwilightRed Hat · Red Hat build of Apache Camel - HawtIO 4EPSS 0.46%via CSAF
CVE-2026-48861Low
2mo ago

mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`

mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target`

▾ Sunlitmint · mintEPSS 0.22%via GHSA
CVE-2026-49753Medium
2mo ago

mint: Content-Length header accepts non-RFC "+" sign prefix

mint: Content-Length header accepts non-RFC "+" sign prefix

▾ Sunlitmint · mintEPSS 0.52%via GHSA
CVE-2026-49754High
2mo ago

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

▾ Twilightmint · mintEPSS 0.52%via GHSA
CVE-2026-48862High
2mo ago

mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS

mint: Unbounded streams map growth via PUSH_PROMISE without follow-up HEADERS

▾ Twilightmint · mintEPSS 0.52%via GHSA
CVE-2026-55252Medium
2mo ago

OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect

OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect

▾ Sunlitopenrundev · github.com/openrundev/openrunvia GHSA
CVE-2026-49851High· 7.5
2mo ago

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

▾ Twilightmistune · mistuneEPSS 0.63%via OSV
CVE-2026-52778Critical· 9.8
2mo ago

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

▾ Midnightyeswiki · yeswiki/yeswikiEPSS 0.94%via GHSA
CVE-2026-54651Medium
2mo ago

pypdf: Possible infinite loop when processing threads/articles in writer

pypdf: Possible infinite loop when processing threads/articles in writer

▾ Sunlitpypdf · pypdfEPSS 0.16%via GHSA
GHSA-387m-935m-c4vwHigh· 7.5
2mo ago

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

▾ Twilightmicronaut · io.micronaut:micronaut-http-clientvia GHSA
GHSA-q6gh-6v2r-hjv3Medium· 6.8
2mo ago

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers

▾ Sunlitmicronaut · io.micronaut:micronaut-http-clientvia GHSA
GHSA-52vm-mxx8-f227High· 7.7
2mo ago

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

▾ Twilightphantom-audio · phantom-audiovia GHSA
CVE-2026-49476High· 7.5
2mo ago

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

▾ Twilightsoupsieve · soupsieveEPSS 0.64%via OSV
CVE-2026-49485High· 7.5
2mo ago

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVEs tagged “ghsa” — page 80 · VulnSea