VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2022-43467High· 7.8
3mo ago

Open Babel has out-of-bounds write in PQS coord_file parser

Open Babel has out-of-bounds write in PQS coord_file parser

▾ Twilightopenbabel · openbabelEPSS 0.83%via GHSA
CVE-2022-43607High· 7.8
3mo ago

Open Babel has out-of-bounds write in MOL2 attribute/value parser

Open Babel has out-of-bounds write in MOL2 attribute/value parser

▾ Twilightopenbabel · openbabelEPSS 0.78%via GHSA
CVE-2022-44451High· 7.8
3mo ago

Open Babel has uninitialized pointer dereference in MSI atom parser

Open Babel has uninitialized pointer dereference in MSI atom parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46280High· 7.8
3mo ago

Open Babel has uninitialized pointer dereference in PQS pFormat

Open Babel has uninitialized pointer dereference in PQS pFormat

▾ Twilightopenbabel · openbabelEPSS 0.83%via GHSA
CVE-2022-46289High· 7.8
3mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser

Open Babel has out-of-bounds write in ORCA nAtoms parser

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46290High· 7.8
3mo ago

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46291High· 7.8
3mo ago

Open Babel has out-of-bounds write in Gaussian translationVectors[]

Open Babel has out-of-bounds write in Gaussian translationVectors[]

▾ Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46293High· 7.8
3mo ago

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2022-46294High· 7.8
3mo ago

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2022-46295High· 7.8
3mo ago

Open Babel has out-of-bounds write in MSI translationVectors[]

Open Babel has out-of-bounds write in MSI translationVectors[]

▾ Twilightopenbabel · openbabelEPSS 0.85%via GHSA
CVE-2026-39379High· 7.1
3mo ago

GeoNetwork has reflected XSS through client-side template injection

GeoNetwork has reflected XSS through client-side template injection

▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-46487High· 7.5
3mo ago

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-53488High· 8.8
3mo ago

github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversi…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.16%via CSAF
CVE-2026-53489Medium· 6.5
3mo ago

github.com/containerd/containerd: containerd: Arbitrary host file read via symlink following in CRI checkpoint restore (CVE-2026-53489)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin incorrectly restores container logs from a checkpoint image. This vulnerability, categorized as a Path Traversal (CWE-61), allow…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.17%via CSAF
CVE-2026-53492High· 8.2
3mo ago

github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.35%via CSAF
CVE-2026-45822High· 7.5
3mo ago

decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)

A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…

▾ TwilightRed Hat · Red Hat Quay 3.12EPSS 0.51%via CSAF
CVE-2026-12243High· 7.5PoC
3mo ago

nltk: NLTK: Information disclosure via path traversal vulnerability (CVE-2026-12243)

A flaw was found in NLTK. An attacker can exploit a path traversal vulnerability by providing specially crafted input to `nltk.data.load()` or `nltk.data.find()`. This allows the attacker to read arbitrary files accessible to the Python pr…

▾ MidnightRed Hat · Red Hat OpenShift AI 3.4via CSAF
CVE-2026-13149High· 7.5
3mo ago

brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)

A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.36%via CSAF
CVE-2025-10995Low· 7.8
3mo ago

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

Open Babel has out-of-bounds write (overlapping memcpy) in zipstream basic_unzip_streambuf::underflow

▾ Sunlitopenbabel · openbabelEPSS 0.25%via GHSA
CVE-2025-10996High· 7.8
3mo ago

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

▾ Twilightopenbabel · openbabelEPSS 0.28%via GHSA
GHSA-55f6-4pr5-c7m5High
3mo ago

Kahi has privilege-drop and socket/log permission issues

Kahi has privilege-drop and socket/log permission issues

▾ Twilightkahiteam · github.com/kahiteam/kahivia GHSA
GHSA-7m8x-qg2j-4m3vHigh· 8.1
3mo ago

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

▾ Twilightfission · github.com/fission/fissionvia GHSA
CVE-2026-49821High· 7.7
3mo ago

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-49822High· 7.7
3mo ago

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-49823High· 7.7
3mo ago

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVE-2026-49824High· 8.5
3mo ago

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-50545Critical· 9.9
3mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

▾ Midnightfission · github.com/fission/fissionEPSS 0.52%via GHSA
CVE-2026-50563Critical· 9.9
3mo ago

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Fission Container Executor Function PodSpec Injection Leading to Node Escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50564Critical· 9.9
3mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50565Medium· 4.9
3mo ago

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

▾ Sunlitfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVEs tagged “ghsa” — page 90 · VulnSea