Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-53518High· 8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-2vg6-77g8-24mpLow· 3.8Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-j8v8-g9cx-5qf4High· 8.3@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
GHSA-59qp-cfj3-rp64Mediumnetfoil has a domain name filter bypass via multiple questions
netfoil has a domain name filter bypass via multiple questions
GHSA-3g4q-2f67-2gvhLownetfoil has a resource leak in LRU cache
netfoil has a resource leak in LRU cache
GHSA-7856-g3gv-9wq8Lownetfoil: Attacker controlled data written to logs
netfoil: Attacker controlled data written to logs
CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
GHSA-fqf6-gxhh-2xhwHighuutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
CVE-2025-46571MediumOpen WebUI allows limited stored XSS vila uploaded html file
Open WebUI allows limited stored XSS vila uploaded html file
CVE-2025-46719HighOpen WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
CVE-2026-26192High· 7.3Open WebUI vulnerable to Stored XSS via iFrame in citations model
Open WebUI vulnerable to Stored XSS via iFrame in citations model
CVE-2026-26193High· 7.3Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
CVE-2026-34225Medium· 4.3Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
CVE-2026-27823CriticalEGroupware has a Remote Code Execution Vulnerability
EGroupware has a Remote Code Execution Vulnerability
CVE-2026-33655High· 7.7New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
CVE-2026-40187HighEGroupware has Authenticated RCE via Malicious eTemplate Upload
EGroupware has Authenticated RCE via Malicious eTemplate Upload
CVE-2026-44342Medium· 5.3New API is vulnerable to CSRF through user email binding
New API is vulnerable to CSRF through user email binding
CVE-2026-44512Medium· 5.5ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
CVE-2026-45016Medium· 6.5EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
CVE-2026-54234High· 7.5vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)
A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…
GHSA-cgfv-jrfp-2r7vHighOpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
GHSA-qrwj-vh9x-gw5vHigh· 8.3Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
CVE-2026-35341High· 7.1mkfifo: permissions of an existing file are changed after FIFO creation fails
mkfifo: permissions of an existing file are changed after FIFO creation fails
CVE-2026-35361Low· 3.4mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
CVE-2026-35381Low· 3.3cut: -s ignored in -z -d '' newline-delimiter mode
cut: -s ignored in -z -d '' newline-delimiter mode
CVE-2026-55501High· 7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVE-2026-54641High· 7.7OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
CVE-2026-54640High· 7.6OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
CVE-2026-55076High· 7.4Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking