Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-50566Critical· 9.9Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation
CVE-2026-48593Mediumoban_web: Unbounded range expansion in cron describe causes memory exhaustion
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
CVE-2026-48592Mediumoban_web missing authorization check on `save-job` event handler
oban_web missing authorization check on `save-job` event handler
CVE-2026-48795High· 8.6@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754
CVE-2026-49835Medium· 5.9Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
CVE-2026-48805LowTwig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVE-2026-48806MediumTwig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVE-2026-48807MediumTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
CVE-2026-48808MediumTwig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
CVE-2026-2704Low· 4.4Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
CVE-2026-2705Low· 5.5Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
CVE-2026-3408Low· 5.5Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
Open Babel has a NULL pointer dereference in CDXML OBAtom::GetExplicitValence
CVE-2025-10994Low· 7.8Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
Open Babel has Use-after-free in GAMESS GAMESSOutputFormat::ReadMolecule
CVE-2026-55219Medium· 5.3Paymenter has race condition in payWithCredit() that enables credit double-spend
Paymenter has race condition in payWithCredit() that enables credit double-spend
CVE-2026-49451High· 7.5Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
CVE-2022-31008Medium· 5.5RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
RabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins
CVE-2023-46118Medium· 4.9RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
CVE-2026-47198High· 8.5Paymenter has URL parameter injection that bypasses paid plan limits at checkout
Paymenter has URL parameter injection that bypasses paid plan limits at checkout
CVE-2026-13676High· 7.5fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its…
CVE-2026-44840High· 7.5PoCDgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
GHSA-fr4h-3cph-29xvHigh· 7.1pnpm: Hoisted install imports lockfile alias outside node_modules
pnpm: Hoisted install imports lockfile alias outside node_modules
GHSA-72r4-9c5j-mj57High· 7.1pnpm: `patch-remove` could delete project-selected files outside the patches directory
pnpm: `patch-remove` could delete project-selected files outside the patches directory
GHSA-qrv3-253h-g69cHigh· 8.2pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
CVE-2026-55677High· 7.5github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy (CVE-2026-55677)
A flaw was found in Echo, a Go web framework. An attacker can exploit a disagreement in URL path decoding between the router and the static file handler. The router processes raw encoded paths, while the static file handler unescapes encod…
CVE-2026-47077HighHackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
CVE-2026-53463Medium· 4.3ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
CVE-2026-48758Medium· 5.4@sigstore/core has DSSE payloadType type-binding failure
@sigstore/core has DSSE payloadType type-binding failure
CVE-2026-48782Medium· 6.8pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
CVE-2026-48788High· 8.2Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
GHSA-5vwr-qchf-q4pfMedium@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths