Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-m492-gv72-xvxjLowKimai Password Reset Link Remains Valid After Password Change
Kimai Password Reset Link Remains Valid After Password Change
CVE-2026-48816Medium· 6.5sigstore-js has Insufficient Verification of Data Authenticity
sigstore-js has Insufficient Verification of Data Authenticity
CVE-2026-48815Medium· 5.9sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)
A flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…
GHSA-5qfp-32cf-69jhHigh· 8.8SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
GHSA-4vgr-h27g-cf9pHigh· 8.1SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation
GHSA-q729-696q-g9pqHigh· 7.5SurrealDB has Denial of Service in JSON parser due to nested objects
SurrealDB has Denial of Service in JSON parser due to nested objects
GHSA-wjjj-24cx-f28gHigh· 7.5SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
SurrealDB has unauthenticated remote DoS via malformed RPC `use` call
GHSA-q8qp-67f9-wr3fMedium· 6.5SurrealDB vulnerable to Denial of Service due to nested types annotations
SurrealDB vulnerable to Denial of Service due to nested types annotations
GHSA-98fx-66cf-fc7cMedium· 6.5SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
GHSA-vjjx-rfw4-rmfcMedium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
GHSA-6vg3-hgrw-p5gfMedium· 5.4SurrealDB has an Authorization Bypass via Composite Record-id Paths
SurrealDB has an Authorization Bypass via Composite Record-id Paths
GHSA-4v76-cw68-4vc9Medium· 6.5SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
SurrealDB: Crafting malicious LIVE queries writes to the database, resulting in DoS, without permission to the table required
GHSA-gcwr-5mrf-fvchMedium· 5.4SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
GHSA-65rj-r9fh-jp2vMedium· 5.3SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
SurrealDB vulnerable to pre-auth memory amplification via unbounded `/sql` WebSocket frames
GHSA-4m82-p8cx-f94jMedium· 4.3SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
GHSA-2wwr-9x6f-88gpMedium· 5.3EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
GHSA-hwmc-r6mf-jh83LowSchema.org has cross-site scripting (XSS) via script break-out in toScript() output
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
GHSA-6c87-g9pw-78fxLow· 3.7Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries
GHSA-3ccm-4qq2-5wrpMedium· 4.3Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
Constrata's coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
GHSA-mjgf-xj26-9qf9High· 7.4pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier
CVE-2026-49987High· 8.8repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
CVE-2026-49988Mediumrepomix: attach_packed_output can bypass file-read secret scanning for supported local files
repomix: attach_packed_output can bypass file-read secret scanning for supported local files
CVE-2025-10997High· 7.8Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies
Open Babel has heap buffer overflow in ChemKin ChemKinFormat::CheckSpecies
CVE-2025-10998Low· 5.5Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
Open Babel has NULL pointer dereference in ChemKinFormat::ReadReactionQualifierLines
CVE-2025-10999Medium· 5.5Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
Open Babel has NULL pointer dereference in CACAO CacaoFormat::SetHilderbrandt
CVE-2025-11000Medium· 4.4Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
Open Babel has out-of-bounds read in PQS lowerit (pre-buffer read)
CVE-2022-37331High· 7.8Open Babel has out-of-bounds write in Gaussian coords_type orientation parser
Open Babel has out-of-bounds write in Gaussian coords_type orientation parser
CVE-2022-41793High· 7.8Open Babel has out-of-bounds write in CSR PadString (title field)
Open Babel has out-of-bounds write in CSR PadString (title field)
CVE-2022-42885High· 7.8Open Babel has uninitialized pointer dereference in GRO residue parser
Open Babel has uninitialized pointer dereference in GRO residue parser