Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-49284High· 7.1SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`
CVE-2026-49352Critical· 9.8PoC9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
CVE-2026-46599High· 7.5golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
CVE-2026-49353High· 7.59router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
GHSA-h72h-ppcx-998pLow· 3.7Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length
CVE-2026-9557Medium· 6.4Mautic Focus component Vulnerable to SSRF
Mautic Focus component Vulnerable to SSRF
CVE-2026-9558Critical· 9.9PoCMautic has Server-Side Template Injection (SSTI) in Theme Templates
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
CVE-2026-9559Critical· 9.9Mautic vulnerable to Path Traversal via Campaign Import
Mautic vulnerable to Path Traversal via Campaign Import
CVE-2026-9808High· 7.1Mautic has an Authorization Bypass in API v2 Endpoints
Mautic has an Authorization Bypass in API v2 Endpoints
CVE-2026-9809High· 7.6PoCMautic has Stored Cross-Site Scripting (XSS) in Projects Component
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
CVE-2026-9811Medium· 5.4PoCMautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector
CVE-2026-50281HighCraft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
CVE-2026-50282HighCraft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-52746High· 7.5jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
GHSA-gj2h-2fpw-fhv9Medium@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
GHSA-g6g7-pvmx-m74pCritical9router: Missing Authorization and OS Command Injection
9router: Missing Authorization and OS Command Injection
GHSA-322x-v876-g883High@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
GHSA-x4hg-hfwf-p9mwMedium@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation
CVE-2026-50194High· 8.2Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-50196High· 7.5Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch
CVE-2026-50200High· 7.5Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-50201Medium· 6.5Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50202Medium· 5.9Steeltoe's static JWKS cache shared across schemes and never invalidated
Steeltoe's static JWKS cache shared across schemes and never invalidated
CVE-2026-50267Medium· 4.7Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted
CVE-2026-50268Low· 1.9Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding
CVE-2026-52830Critical· 9.4fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection
CVE-2026-50279HighCraft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
CVE-2026-50280MediumCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
CVE-2026-50283MediumCraft CMS: Unauthorized Deletion of Source Assets During File Replacement
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-50284HighCraft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets