Tagged “ghsa”
CVEs tagged ghsa, newest first.
3811 CVEsRSS
CVE-2026-68523High· 7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…
CVE-2026-65608High· 8.8Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
CVE-2026-69088High· 8.1Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
CVE-2026-69089HighGrav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
CVE-2026-85716Low· 3.7The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM…
CVE-2026-85720Medium· 5.9The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose p…
CVE-2026-86039High· 8.2PoClibp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…
CVE-2026-86038High· 7.5PoClibp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …
CVE-2026-86000Medium· 5.3PoCSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…
CVE-2026-85999Medium· 5.3PoCSoup Sieve is a CSS selector library designed to be used with Beautiful Soup 4
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …
CVE-2026-85721High· 7.5PoCThe AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelM…
CVE-2026-85717Medium· 6.8The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redire…
CVE-2026-81868Medium· 6.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCe…
CVE-2026-81515High· 7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, and an unrecognize…
CVE-2026-75523Medium· 5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs t…
CVE-2026-61449Medium· 6.5Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
CVE-2026-85078Medium· 6.5Sanic is an opensource python web server/framework
Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer.…
CVE-2026-79752Critical· 9.2PoCCakePHP is a rapid development framework for PHP
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBui…
CVE-2026-71538High· 8.5@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not provide the npm CLI path, can construct a she…
CVE-2026-63472Critical· 9.1PoCVendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing…
CVE-2026-63461Medium· 5.3Vendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied filters using the caller-controlled filterOperat…
CVE-2026-63460High· 7.5PoCVendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service…
CVE-2026-63459High· 8.7PoCVendure is an open-source headless commerce platform
Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrat…
CVE-2026-61793Medium· 6.9PoCNuxt OG Image generates OG Images with Vue templates in Nuxt
Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…
CVE-2026-55061Low· 1.0uniget is a universal installer and updater for (container) tools
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…
CVE-2026-55062High· 8.4PoCuniget is a universal installer and updater for (container) tools
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…
CVE-2026-54546Medium· 5.0PoCCloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK
CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…
CVE-2026-50285High· 7.5PoCPomerium is an identity and context-aware access proxy
Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V…
CVE-2026-54504High· 8.8PoCMCP Documentation Server is a local-first document management and semantic search server for AI coding agents
MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…
CVE-2026-54495Medium· 4.3The OpenFeature Operator allows users to expose feature flags to applications
The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME…