Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-35369Medium· 5.5kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
CVE-2026-35371Low· 3.3id: pretty-print uses effective GID instead of effective UID for name lookup
id: pretty-print uses effective GID instead of effective UID for name lookup
CVE-2026-35349Medium· 6.7rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
CVE-2026-35353Low· 3.3mkdir: -m exposes directory with umask perms before chmod (race window)
mkdir: -m exposes directory with umask perms before chmod (race window)
CVE-2026-35370Medium· 4.4id: groups= computed from real GID instead of effective GID
id: groups= computed from real GID instead of effective GID
CVE-2026-35347Medium· 4.4comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
CVE-2026-35363Medium· 5.6rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
CVE-2026-35358Medium· 4.4cp: -R reads device nodes as streams, destroying device semantics
cp: -R reads device nodes as streams, destroying device semantics
CVE-2026-35365Medium· 6.6mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
CVE-2026-35362Low· 3.6uucore: safe_traversal TOCTOU protection only enabled on Linux
uucore: safe_traversal TOCTOU protection only enabled on Linux
CVE-2026-35366Medium· 4.4printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
CVE-2026-53486Critical· 9.1Decompress: Archive extraction can create files and links outside of the target directory
Decompress: Archive extraction can create files and links outside of the target directory
GHSA-x76w-8c62-48mgMediumCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
CVE-2026-54760CriticalLangroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
CVE-2026-54769Critical· 10.0Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
CVE-2026-54771High· 8.1Langroid: handle_message() executes user-supplied tool JSON without sender verification
Langroid: handle_message() executes user-supplied tool JSON without sender verification
CVE-2026-53624Medium· 4.8GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
CVE-2026-53935Medium· 6.9CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CVE-2026-35339Medium· 5.5chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
CVE-2026-49445Critical· 9.2Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
GHSA-7jvp-hj45-2f2mHighScriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
CVE-2026-55787High· 7.1flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
CVE-2026-55786High· 8.4flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
CVE-2026-35338High· 7.3chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)
CVE-2022-46292High· 7.8Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
CVE-2026-59800Critical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
CVE-2026-2092High· 7.7Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
GHSA-j5mc-p8qg-39j7LowKimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
GHSA-2v8p-fqpx-2q3wMedium· 6.2jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
jxl-oxide: integer subtraction overflow panic in cluster_from_table via crafted JXL input (DoS)
GHSA-66m8-c62j-h6v5Medium· 6.2jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow
jxl-oxide: `FrameBuffer::new` creates out-of-bounds slices on overflow