VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-m492-gv72-xvxjLow
3mo ago

Kimai Password Reset Link Remains Valid After Password Change

Kimai Password Reset Link Remains Valid After Password Change

▾ Sunlitkimai · kimai/kimaivia GHSA
CVE-2026-48816Medium· 6.5
3mo ago

sigstore-js has Insufficient Verification of Data Authenticity

sigstore-js has Insufficient Verification of Data Authenticity

▾ Sunlitsigstore · @sigstore/verifyEPSS 0.16%via GHSA
CVE-2026-48815Medium· 5.9
3mo ago

sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)

A flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.19%via CSAF
GHSA-5qfp-32cf-69jhHigh· 8.8
3mo ago

SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers

SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-4vgr-h27g-cf9pHigh· 8.1
3mo ago

SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation

SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-q729-696q-g9pqHigh· 7.5
3mo ago

SurrealDB has Denial of Service in JSON parser due to nested objects

SurrealDB has Denial of Service in JSON parser due to nested objects

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-wjjj-24cx-f28gHigh· 7.5
3mo ago

SurrealDB has unauthenticated remote DoS via malformed RPC `use` call

SurrealDB has unauthenticated remote DoS via malformed RPC `use` call

▾ Twilightsurrealdb · surrealdbvia GHSA
GHSA-q8qp-67f9-wr3fMedium· 6.5
3mo ago

SurrealDB vulnerable to Denial of Service due to nested types annotations

SurrealDB vulnerable to Denial of Service due to nested types annotations

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-98fx-66cf-fc7cMedium· 6.5
3mo ago

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-vjjx-rfw4-rmfcMedium· 6.5
3mo ago

SurrealDB: Graph traversal bypasses table SELECT permissions

SurrealDB: Graph traversal bypasses table SELECT permissions

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-6vg3-hgrw-p5gfMedium· 5.4
3mo ago

SurrealDB has an Authorization Bypass via Composite Record-id Paths

SurrealDB has an Authorization Bypass via Composite Record-id Paths

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-4v76-cw68-4vc9Medium· 6.5
3mo ago

SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required

SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-gcwr-5mrf-fvchMedium· 5.4
3mo ago

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-65rj-r9fh-jp2vMedium· 5.3
3mo ago

SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames

SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-4m82-p8cx-f94jMedium· 4.3
3mo ago

SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls

SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-2wwr-9x6f-88gpMedium· 5.3
3mo ago

EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components

EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components

▾ Sunliteasycorp · easycorp/easyadmin-bundlevia GHSA
GHSA-hwmc-r6mf-jh83Low
3mo ago

Schema.org has cross-site scripting (XSS) via script break-out in toScript() output

Schema.org has cross-site scripting (XSS) via script break-out in toScript() output

▾ Sunlitspatie · spatie/schema-orgvia GHSA
GHSA-6c87-g9pw-78fxLow· 3.7
3mo ago

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
GHSA-3ccm-4qq2-5wrpMedium· 4.3
3mo ago

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts

▾ Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
CVE-2026-49981High
3mo ago

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

▾ Twilighttwig · twig/twigEPSS 0.36%via GHSA
GHSA-mjgf-xj26-9qf9High· 7.4
3mo ago

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier

▾ Twilightpay · payvia GHSA
CVE-2026-49987High· 8.8
3mo ago

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

▾ Twilightrepomix · repomixEPSS 0.70%via GHSA
CVE-2026-49988Medium
3mo ago

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

repomix: attach_packed_output can bypass file-read secret scanning for supported local files

▾ Sunlitrepomix · repomixEPSS 0.18%via GHSA
CVE-2025-10997High· 7.8
3mo ago

Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies

▾ Twilightopenbabel · openbabelEPSS 0.28%via GHSA
CVE-2025-10998Low· 5.5
3mo ago

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines

▾ Sunlitopenbabel · openbabelEPSS 0.21%via GHSA
CVE-2025-10999Medium· 5.5
3mo ago

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt

▾ Sunlitopenbabel · openbabelEPSS 0.25%via GHSA
CVE-2025-11000Medium· 4.4
3mo ago

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)

▾ Sunlitopenbabel · openbabelEPSS 0.24%via GHSA
CVE-2022-37331High· 7.8
3mo ago

Open Babel has out-of-bounds write in Gaussian coords_type orientation parser

Open Babel has out-of-bounds write in Gaussian coords_type orientation parser

▾ Twilightopenbabel · openbabelEPSS 0.68%via GHSA
CVE-2022-41793High· 7.8
3mo ago

Open Babel has out-of-bounds write in CSR PadString (title field)

Open Babel has out-of-bounds write in CSR PadString (title field)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-42885High· 7.8
3mo ago

Open Babel has uninitialized pointer dereference in GRO residue parser

Open Babel has uninitialized pointer dereference in GRO residue parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVEs tagged “ghsa” — page 89 · VulnSea