Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2022-43467High· 7.8Open Babel has out-of-bounds write in PQS coord_file parser
Open Babel has out-of-bounds write in PQS coord_file parser
CVE-2022-43607High· 7.8Open Babel has out-of-bounds write in MOL2 attribute/value parser
Open Babel has out-of-bounds write in MOL2 attribute/value parser
CVE-2022-44451High· 7.8Open Babel has uninitialized pointer dereference in MSI atom parser
Open Babel has uninitialized pointer dereference in MSI atom parser
CVE-2022-46280High· 7.8Open Babel has uninitialized pointer dereference in PQS pFormat
Open Babel has uninitialized pointer dereference in PQS pFormat
CVE-2022-46289High· 7.8Open Babel has out-of-bounds write in ORCA nAtoms parser
Open Babel has out-of-bounds write in ORCA nAtoms parser
CVE-2022-46290High· 7.8Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)
Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)
CVE-2022-46291High· 7.8Open Babel has out-of-bounds write in Gaussian translationVectors[]
Open Babel has out-of-bounds write in Gaussian translationVectors[]
CVE-2022-46293High· 7.8Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
CVE-2022-46294High· 7.8Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)
Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)
CVE-2022-46295High· 7.8Open Babel has out-of-bounds write in MSI translationVectors[]
Open Babel has out-of-bounds write in MSI translationVectors[]
CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection
GeoNetwork has reflected XSS through client-side template injection
CVE-2026-46487High· 7.5GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
CVE-2026-53488High· 8.8github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversi…
CVE-2026-53489Medium· 6.5github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore (CVE-2026-53489)
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allow…
CVE-2026-53492High· 8.2github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…
CVE-2026-45822High· 7.5decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)
A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…
CVE-2026-12243High· 7.5PoCnltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)
A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…
CVE-2026-13149High· 7.5brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…
CVE-2025-10995Low· 7.8Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow
CVE-2025-10996High· 7.8Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
GHSA-55f6-4pr5-c7m5HighKahi has privilege-drop and socket/log permission issues
Kahi has privilege-drop and socket/log permission issues
GHSA-7m8x-qg2j-4m3vHigh· 8.1Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec
CVE-2026-49821High· 7.7Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration
CVE-2026-49822High· 7.7Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance
CVE-2026-49823High· 7.7Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook
CVE-2026-49824High· 8.5Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook
CVE-2026-50545Critical· 9.9Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover
CVE-2026-50563Critical· 9.9Fission Container Executor Function PodSpec Injection Leading to Node Escape
Fission Container Executor Function PodSpec Injection Leading to Node Escape
CVE-2026-50564Critical· 9.9Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape
CVE-2026-50565Medium· 4.9Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container
Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container