VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-49284High· 7.1
2mo ago

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`

▾ Twilightsimplesamlphp · simplesamlphp/simplesamlphpEPSS 0.22%via GHSA
CVE-2026-49352Critical· 9.8PoC
2mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

▾ Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-46599High· 7.5
2mo ago

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

▾ Twilightx · golang.org/x/imageEPSS 0.63%via GHSA
CVE-2026-49353High· 7.5
2mo ago

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

▾ Twilight9router · 9routerEPSS 0.36%via GHSA
GHSA-h72h-ppcx-998pLow· 3.7
2mo ago

Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length

Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length

▾ Sunlitzebra-network · zebra-networkvia GHSA
CVE-2026-9557Medium· 6.4
2mo ago

Mautic Focus component Vulnerable to SSRF

Mautic Focus component Vulnerable to SSRF

▾ Sunlitmautic · mautic/coreEPSS 0.23%via GHSA
CVE-2026-9558Critical· 9.9PoC
2mo ago

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

Mautic has Server-Side Template Injection (SSTI) in Theme Templates

▾ Abyssalmautic · mautic/coreEPSS 0.79%via GHSA
CVE-2026-9559Critical· 9.9
2mo ago

Mautic vulnerable to Path Traversal via Campaign Import

Mautic vulnerable to Path Traversal via Campaign Import

▾ Midnightmautic · mautic/coreEPSS 0.93%via GHSA
CVE-2026-9808High· 7.1
2mo ago

Mautic has an Authorization Bypass in API v2 Endpoints

Mautic has an Authorization Bypass in API v2 Endpoints

▾ Twilightmautic · mautic/coreEPSS 0.34%via GHSA
CVE-2026-9809High· 7.6PoC
2mo ago

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

Mautic has Stored Cross-Site Scripting (XSS) in Projects Component

▾ Midnightmautic · mautic/coreEPSS 0.29%via GHSA
CVE-2026-9811Medium· 5.4PoC
2mo ago

Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector

Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector

▾ Twilightmautic · mautic/coreEPSS 0.23%via GHSA
CVE-2026-50281High
2mo ago

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

▾ Twilightcraftcms · craftcms/cmsEPSS 0.43%via GHSA
CVE-2026-50282High
2mo ago

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

▾ Twilightcraftcms · craftcms/cmsEPSS 0.35%via GHSA
CVE-2026-52746High· 7.5
2mo ago

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

▾ Twilightjsonata · jsonataEPSS 0.69%via GHSA
GHSA-gj2h-2fpw-fhv9Medium
2mo ago

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

▾ Sunlitnuxt · @nuxt/uivia GHSA
GHSA-g6g7-pvmx-m74pCritical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routervia GHSA
GHSA-322x-v876-g883High
2mo ago

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write

▾ Twilightasymmetric-effort · @asymmetric-effort/nogginlessdomvia GHSA
GHSA-x4hg-hfwf-p9mwMedium
2mo ago

@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation

@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation

▾ Sunlitasymmetric-effort · @asymmetric-effort/nogginlessdomvia GHSA
CVE-2026-50194High· 8.2
2mo ago

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.41%via GHSA
CVE-2026-50196High· 7.5
2mo ago

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

▾ TwilightSteeltoe · Steeltoe.Discovery.EurekaEPSS 0.61%via GHSA
CVE-2026-50200High· 7.5
2mo ago

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.31%via GHSA
CVE-2026-50201Medium· 6.5
2mo ago

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

▾ SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.40%via GHSA
CVE-2026-50202Medium· 5.9
2mo ago

Steeltoe's static JWKS cache shared across schemes and never invalidated

Steeltoe's static JWKS cache shared across schemes and never invalidated

▾ SunlitSteeltoe · Steeltoe.Security.Authentication.JwtBearerEPSS 0.47%via GHSA
CVE-2026-50267Medium· 4.7
2mo ago

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

Steeltoe: TLS private keys written to /tmp with default permissions, never deleted

▾ SunlitSteeltoe · Steeltoe.Configuration.AbstractionsEPSS 0.08%via GHSA
CVE-2026-50268Low· 1.9
2mo ago

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding

▾ SunlitSteeltoe · Steeltoe.Configuration.EncryptionEPSS 0.06%via GHSA
CVE-2026-52830Critical· 9.4
2mo ago

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection

▾ Midnightfast-mcp-telegram · fast-mcp-telegramEPSS 0.65%via GHSA
CVE-2026-50279High
2mo ago

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

▾ Twilightcraftcms · craftcms/cmsEPSS 0.36%via GHSA
CVE-2026-50280Medium
2mo ago

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.40%via GHSA
CVE-2026-50283Medium
2mo ago

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.36%via GHSA
CVE-2026-50284High
2mo ago

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

▾ Twilightcraftcms · craftcms/cmsEPSS 0.39%via GHSA
CVEs tagged “ghsa” — page 85 · VulnSea