VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-53727High
2mo ago

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`

▾ Twilightcss_parser · css_parserEPSS 0.51%via GHSA
GHSA-c43v-4cr8-6mvpLow
2mo ago

Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read

Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-86vw-x4ww-x467High
2mo ago

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

▾ Twilightcraftcms · craftcms/cmsvia GHSA
GHSA-382c-vx95-w3p5Medium· 6.5
2mo ago

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

▾ Sunlitjsonbored · @jsonbored/gittensory-mcpvia GHSA
GHSA-4wj4-79rr-pvffMedium· 4.8
2mo ago

Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-55874High· 7.7
2mo ago

SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874)

A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user,…

▾ TwilightRed Hat · Cryostat 4 on RHEL 9EPSS 0.61%via CSAF
CVE-2026-59887High· 7.5
2mo ago

linkify-it: linkify-it: Denial of Service via crafted mailto: links (CVE-2026-59887)

A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invok…

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.64%via CSAF
CVE-2026-59879Medium· 5.3⚖ disputed
2mo ago

immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)

A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a partic…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via CSAF
CVE-2026-59874High· 7.5
2mo ago

tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)

A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header c…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-59873High· 7.5
2mo ago

tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)

A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This o…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-59871Medium· 5.3
2mo ago

node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)

A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.64%via CSAF
CVE-2026-59877High· 7.5⚖ disputed
2mo ago

protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)

A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an op…

▾ TwilightRed Hat · Red Hat OpenShift Service Mesh 3.3EPSS 0.67%via CSAF
CVE-2026-49471High· 8.3
2mo ago

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

▾ Twilightserena-agent · serena-agentEPSS 0.37%via GHSA
CVE-2026-50197High· 8.7
2mo ago

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests

▾ Twilightzalando · github.com/zalando/skipperEPSS 0.55%via GHSA
CVE-2026-53634Medium· 4.3
2mo ago

Sharp Missing Authorization Check in Quick Creation Command Endpoints

Sharp Missing Authorization Check in Quick Creation Command Endpoints

▾ Sunlitcode16 · code16/sharpEPSS 0.37%via GHSA
GHSA-mxwc-wh95-pw4gMedium· 5.3
2mo ago

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler

▾ Sunlittrapster · trapstervia GHSA
GHSA-q95x-7g78-rccvMedium
2mo ago

OneRingBuf has a Use After Free Vulnerability

OneRingBuf has a Use After Free Vulnerability

▾ Sunlitoneringbuf · oneringbufvia GHSA
CVE-2026-56812High· 7.5PoC
2mo ago

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…

▾ Midnightphoenixframework · phoenixEPSS 0.80%via NVD
CVE-2026-56811High· 7.5
2mo ago

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with…

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with…

▾ Twilightphoenixframework · phoenixEPSS 0.78%via NVD
CVE-2026-50127Medium· 5.9
2mo ago

Weblate SSRF: outbound URL guard misses some private ranges

Weblate SSRF: outbound URL guard misses some private ranges

▾ Sunlitweblate · weblateEPSS 0.47%via GHSA
GHSA-gq4g-fpc9-vjfqLow
2mo ago

Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection

Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection

▾ Sunlitweb-auth · web-auth/webauthn-libvia GHSA
GHSA-cwv4-h3j5-w3cfLow· 3.7
2mo ago

rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

▾ Sunlitrama · ramavia GHSA
GHSA-q855-8rh5-jfgqMedium· 6.5
2mo ago

ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path

ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path

▾ Sunlitha-mcp · ha-mcpvia GHSA
GHSA-f66q-9rf6-8795Medium
2mo ago

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

▾ Sunlitflask-security-too · flask-security-toovia OSV
GHSA-p2fr-6hmx-4528Medium· 6.4
2mo ago

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

▾ Sunlitbetter-auth · @better-auth/oauth-providervia GHSA
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

▾ Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53516High· 8.3
2mo ago

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

▾ Twilightbetter-auth · better-authEPSS 0.29%via GHSA
GHSA-86j7-9j95-vpqjHigh· 7.7
2mo ago

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

▾ Twilightbetter-auth · better-authvia GHSA
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

▾ Twilightbetter-auth · better-authvia GHSA
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVEs tagged “ghsa” — page 81 · VulnSea