Tagged “ghsa”
CVEs tagged ghsa, newest first.
3826 CVEsRSS
CVE-2026-45045Medium· 5.3GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
CVE-2026-9795High· 7.3Keycloak has privilege escalation via improper scope mapping enforcement
Keycloak has privilege escalation via improper scope mapping enforcement
CVE-2026-50151Medium· 5.9oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)
A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…
CVE-2026-50162Medium· 5.3oras-go: oras-go: File store write outside working directory via symlink traversal (CVE-2026-50162)
A flaw was found in oras-go. The file content store, intended to confine writes to a specified working directory, does not properly account for symbolic link (symlink) traversal. A remote attacker, by providing a specially crafted blob tit…
CVE-2026-50163High· 7.1`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
CVE-2026-53712HighOnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms
OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms
GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
CVE-2026-53943Critical· 9.6Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
OpenClaw MCP SSE redirects could forward Authorization headers
GHSA-6g9v-7gq3-p2c6Medium· 4.3SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
GHSA-fpxg-5xmv-922mMedium· 4.3SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
GHSA-f82j-v89j-mf86Medium· 4.3SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
GHSA-6wqw-vhfr-9999Medium· 4.3SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
SurrealDB: Authenticated subscribers can read records hidden by SELECT permissions via LIVE subscriptions
GHSA-97vg-427p-8hx5Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
GHSA-wp87-mgvq-5j93Medium· 6.5SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization
GHSA-c8jx-96c9-8xrpMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
SurrealDB: Field-level SELECT permissions bypassed via indexed COUNT fast paths
GHSA-fwg2-gr34-q3w8Medium· 4.3SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
CVE-2026-49997Medium· 5.4SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVE-2026-49998High· 8.2Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
GHSA-j6hm-v3x2-qv6jLowland.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory
land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory
CVE-2026-44938High· 8.8Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-44937High· 7.5Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components
CVE-2026-44939Critical· 9.6Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
CVE-2026-44936Medium· 5.0Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
CVE-2026-44935Critical· 9.9Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
CVE-2026-41053High· 8.8Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
CVE-2026-48819Medium· 4.8@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
CVE-2026-48824Medium· 5.3Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
CVE-2026-41052Critical· 8.4Rancher has Privilege Escalation from Project Owner to Host
Rancher has Privilege Escalation from Project Owner to Host
CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens