VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-35369Medium· 5.5
2mo ago

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

▾ Sunlituu_kill · uu_killEPSS 0.15%via GHSA
CVE-2026-35371Low· 3.3
2mo ago

id: pretty-print uses effective GID instead of effective UID for name lookup

id: pretty-print uses effective GID instead of effective UID for name lookup

▾ Sunlituu_id · uu_idEPSS 0.14%via GHSA
CVE-2026-35349Medium· 6.7
2mo ago

rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)

rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)

▾ Sunlituu_rm · uu_rmEPSS 0.21%via GHSA
CVE-2026-35353Low· 3.3
2mo ago

mkdir: -m exposes directory with umask perms before chmod (race window)

mkdir: -m exposes directory with umask perms before chmod (race window)

▾ Sunlituu_mkdir · uu_mkdirEPSS 0.12%via GHSA
CVE-2026-35370Medium· 4.4
2mo ago

id: groups= computed from real GID instead of effective GID

id: groups= computed from real GID instead of effective GID

▾ Sunlituu_id · uu_idEPSS 0.13%via GHSA
CVE-2026-35347Medium· 4.4
2mo ago

comm: FIFO/pipe inputs are drained before comparison (data loss / hang)

comm: FIFO/pipe inputs are drained before comparison (data loss / hang)

▾ Sunlituu_comm · uu_commEPSS 0.15%via GHSA
CVE-2026-35363Medium· 5.6
2mo ago

rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection

rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection

▾ Sunlituu_rm · uu_rmEPSS 0.17%via GHSA
CVE-2026-35358Medium· 4.4
2mo ago

cp: -R reads device nodes as streams, destroying device semantics

cp: -R reads device nodes as streams, destroying device semantics

▾ Sunlituu_cp · uu_cpEPSS 0.18%via GHSA
CVE-2026-35365Medium· 6.6
2mo ago

mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)

mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)

▾ Sunlituu_mv · uu_mvEPSS 0.19%via GHSA
CVE-2026-35362Low· 3.6
2mo ago

uucore: safe_traversal TOCTOU protection only enabled on Linux

uucore: safe_traversal TOCTOU protection only enabled on Linux

▾ Sunlituucore · uucoreEPSS 0.20%via GHSA
CVE-2026-35366Medium· 4.4
2mo ago

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

▾ Sunlituu_printenv · uu_printenvEPSS 0.19%via GHSA
CVE-2026-53486Critical· 9.1
2mo ago

Decompress: Archive extraction can create files and links outside of the target directory

Decompress: Archive extraction can create files and links outside of the target directory

▾ Midnightxhmikosr · @xhmikosr/decompressEPSS 0.75%via GHSA
GHSA-x76w-8c62-48mgMedium
2mo ago

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-54760Critical
2mo ago

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

▾ Midnightlangroid · langroidEPSS 0.65%via GHSA
CVE-2026-54769Critical· 10.0
2mo ago

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.91%via GHSA
CVE-2026-54771High· 8.1
2mo ago

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Langroid: handle_message() executes user-supplied tool JSON without sender verification

▾ Twilightlangroid · langroidEPSS 0.39%via GHSA
CVE-2026-53624Medium· 4.8
2mo ago

GoFiber never set HSTS header in helmet middleware due to incorrect protocol check

GoFiber never set HSTS header in helmet middleware due to incorrect protocol check

▾ Sunlitgofiber · github.com/gofiber/fiberEPSS 0.21%via GHSA
CVE-2026-53935Medium· 6.9
2mo ago

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.34%via GHSA
CVE-2026-35339Medium· 5.5
2mo ago

chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)

chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)

▾ Sunlituu_chmod · uu_chmodEPSS 0.16%via GHSA
CVE-2026-49445Critical· 9.2
2mo ago

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

▾ Midnightcilium · github.com/cilium/ciliumEPSS 0.17%via GHSA
GHSA-7jvp-hj45-2f2mHigh
2mo ago

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

▾ TwilightScriban · Scribanvia GHSA
CVE-2026-55787High· 7.1
2mo ago

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

▾ Twilightflyto-core · flyto-corevia GHSA
CVE-2026-55786High· 8.4
2mo ago

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

▾ Twilightflyto-core · flyto-corevia GHSA
CVE-2026-35338High· 7.3
2mo ago

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

▾ Twilightuu_chmod · uu_chmodEPSS 0.20%via GHSA
CVE-2022-46292High· 7.8
2mo ago

Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)

Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2026-59800Critical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routerEPSS 2.0%via GHSA
CVE-2026-2092High· 7.7
2mo ago

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.31%via GHSA
GHSA-j5mc-p8qg-39j7Low
2mo ago

Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

▾ Sunlitkimai · kimai/kimaivia GHSA
GHSA-2v8p-fqpx-2q3wMedium· 6.2
2mo ago

jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)

jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)

▾ Sunlitjxl-modular · jxl-modularvia GHSA
GHSA-66m8-c62j-h6v5Medium· 6.2
2mo ago

jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow

jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow

▾ Sunlitjxl-oxide · jxl-oxidevia GHSA
CVEs tagged “ghsa” — page 84 · VulnSea