Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-53727HighRuby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
GHSA-c43v-4cr8-6mvpLowCraft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
GHSA-86vw-x4ww-x467HighCraft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
GHSA-382c-vx95-w3p5Medium· 6.5Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
GHSA-4wj4-79rr-pvffMedium· 4.8Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
CVE-2026-55874High· 7.7SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874)
A flaw was found in SeaweedFS, a distributed storage system. The S3 API gateway in SeaweedFS does not properly validate `X-Amz-Copy-Source` headers, specifically failing to reject "dot-dot" path segments. This allows an authenticated user,…
CVE-2026-59887High· 7.5linkify-it: linkify-it: Denial of Service via crafted mailto: links (CVE-2026-59887)
A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invok…
CVE-2026-59879Medium· 5.3⚖ disputedimmutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations (CVE-2026-59879)
A flaw was found in Immutable.js, a library providing persistent immutable data structures. This vulnerability occurs when specific List operations, such as List#set or List#setSize, are provided with an index or size value within a partic…
CVE-2026-59874High· 7.5tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header c…
CVE-2026-59873High· 7.5tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This o…
CVE-2026-59871Medium· 5.3node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)
A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…
CVE-2026-59877High· 7.5⚖ disputedprotobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877)
A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an op…
CVE-2026-49471High· 8.3Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
CVE-2026-50197High· 8.7Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
CVE-2026-53634Medium· 4.3Sharp Missing Authorization Check in Quick Creation Command Endpoints
Sharp Missing Authorization Check in Quick Creation Command Endpoints
GHSA-mxwc-wh95-pw4gMedium· 5.3Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
GHSA-q95x-7g78-rccvMediumOneRingBuf has a Use After Free Vulnerability
OneRingBuf has a Use After Free Vulnerability
CVE-2026-56812High· 7.5PoCImproper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…
Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every…
CVE-2026-56811High· 7.5Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with…
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with…
CVE-2026-50127Medium· 5.9Weblate SSRF: outbound URL guard misses some private ranges
Weblate SSRF: outbound URL guard misses some private ranges
GHSA-gq4g-fpc9-vjfqLowWebauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
GHSA-cwv4-h3j5-w3cfLow· 3.7rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
GHSA-q855-8rh5-jfgqMedium· 6.5ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
GHSA-f66q-9rf6-8795MediumFlask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
GHSA-p2fr-6hmx-4528Medium· 6.4@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
CVE-2026-53514High· 7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-53516High· 8.3Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-86j7-9j95-vpqjHigh· 7.7Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-9h47-pqcx-hjr4High· 8.7Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption