VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3826 CVEsRSS

CVE-2026-45045Medium· 5.3
2mo ago

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.46%via GHSA
CVE-2026-9795High· 7.3
3mo ago

Keycloak has privilege escalation via improper scope mapping enforcement

Keycloak has privilege escalation via improper scope mapping enforcement

▾ Twilightkeycloak · org.keycloak:keycloak-servicesEPSS 0.49%via GHSA
CVE-2026-50151Medium· 5.9
3mo ago

oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)

A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.49%via CSAF
CVE-2026-50162Medium· 5.3
3mo ago

oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)

A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…

▾ SunlitRed Hat · Red Hat Edge Manager 1.1EPSS 0.51%via CSAF
CVE-2026-50163High· 7.1
3mo ago

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution

▾ Twilightoras-go · oras.land/oras-go/v2EPSS 0.43%via GHSA
CVE-2026-53712High
3mo ago

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

▾ Twilightongres · com.ongres.scram:scram-clientEPSS 0.26%via GHSA
GHSA-vh4v-2xq2-g5cgMedium
3mo ago

ORAS Go forwards registry credentials across registry redirects

ORAS Go forwards registry credentials across registry redirects

▾ Sunlitoras-go · oras.land/oras-go/v2via GHSA
CVE-2026-53943Critical· 9.6
3mo ago

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

▾ Midnightghost · ghostEPSS 0.45%via GHSA
GHSA-9c3v-684m-579cMedium· 6.5
3mo ago

OpenClaw MCP SSE redirects could forward Authorization headers

OpenClaw MCP SSE redirects could forward Authorization headers

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-6g9v-7gq3-p2c6Medium· 4.3
3mo ago

SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages

SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-fpxg-5xmv-922mMedium· 4.3
3mo ago

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-f82j-v89j-mf86Medium· 4.3
3mo ago

SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission

SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-6wqw-vhfr-9999Medium· 4.3
3mo ago

SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions

SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-97vg-427p-8hx5Medium· 6.4
3mo ago

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-wp87-mgvq-5j93Medium· 6.5
3mo ago

SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization

SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-c8jx-96c9-8xrpMedium· 4.3
3mo ago

SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths

SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-fwg2-gr34-q3w8Medium· 4.3
3mo ago

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49997Medium· 5.4
3mo ago

SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted

SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted

▾ Sunlitsurrealdb · surrealdbEPSS 0.35%via GHSA
CVE-2026-49998High· 8.2
3mo ago

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass

▾ Twilightcentrifugal · github.com/centrifugal/centrifugo/v6EPSS 0.27%via GHSA
GHSA-j6hm-v3x2-qv6jLow
3mo ago

land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory

land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory

▾ Sunlitoras · land.oras:oras-java-sdkvia GHSA
CVE-2026-44938High· 8.8
3mo ago

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

▾ Twilightrancher · github.com/rancher/fleetEPSS 0.44%via GHSA
CVE-2026-44937High· 7.5
3mo ago

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

▾ Twilightrancher · github.com/rancher/fleetEPSS 0.42%via GHSA
CVE-2026-44939Critical· 9.6
3mo ago

Rancher vulnerable to command injection through unsanitized YAML parameter

Rancher vulnerable to command injection through unsanitized YAML parameter

▾ Midnightrancher · github.com/rancher/rancherEPSS 1.3%via GHSA
CVE-2026-44936Medium· 5.0
3mo ago

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml

▾ Sunlitrancher · github.com/rancher/fleetEPSS 0.35%via GHSA
CVE-2026-44935Critical· 9.9
3mo ago

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer

▾ Midnightrancher · github.com/rancher/fleetEPSS 0.49%via GHSA
CVE-2026-41053High· 8.8
3mo ago

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

Rancher has over-inclusive team membership expansion in GitHub App authentication provider

▾ Twilightrancher · github.com/rancher/rancherEPSS 0.52%via OSV
CVE-2026-48819Medium· 4.8
3mo ago

@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key

@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key

▾ Sunlithey-api · @hey-api/openapi-tsEPSS 0.35%via GHSA
CVE-2026-48824Medium· 5.3
3mo ago

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.54%via GHSA
CVE-2026-41052Critical· 8.4
3mo ago

Rancher has Privilege Escalation from Project Owner to Host

Rancher has Privilege Escalation from Project Owner to Host

▾ Midnightrancher · github.com/rancher/rancherEPSS 0.42%via GHSA
CVE-2026-48978Low
3mo ago

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens

▾ Sunlitoras-go · oras.land/oras-go/v2EPSS 0.26%via GHSA
CVEs tagged “ghsa” — page 88 · VulnSea