VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-vgrc-hq28-p3xpHigh· 7.4
3mo ago

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

▾ Twilightapernet · github.com/apernet/hysteria/core/v2via GHSA
GHSA-qh5x-rfwf-rvfvHigh· 7.5
3mo ago

Hysteria vulnerable to server crash when max_datagram_frame_size very small

Hysteria vulnerable to server crash when max_datagram_frame_size very small

▾ Twilightapernet · github.com/apernet/hysteriavia GHSA
GHSA-jqc5-2p7q-fqfcHigh· 7.5
3mo ago

Hysteria: http large header with sniff cause server DoS

Hysteria: http large header with sniff cause server DoS

▾ Twilightapernet · github.com/apernet/hysteriavia GHSA
GHSA-72w7-mf9g-733pMedium· 6.4
3mo ago

nono-py has proxy-only network fallback bypass on older Linux kernels

nono-py has proxy-only network fallback bypass on older Linux kernels

▾ Sunlitnono-py · nono-pyvia GHSA
CVE-2026-48797Critical
3mo ago

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

▾ Midnightbackpropagate · backpropagateEPSS 0.57%via OSV
GHSA-9j7f-3r4p-pwh6Medium· 5.2
3mo ago

nono-py vulnerable to authorization bypass / policy confusion

nono-py vulnerable to authorization bypass / policy confusion

▾ Sunlitnono-py · nono-pyvia GHSA
GHSA-m8j6-rc5x-wv36Medium· 5.2
3mo ago

nono-py's policy JSON accepts unknown security fields

nono-py's policy JSON accepts unknown security fields

▾ Sunlitnono-py · nono-pyvia GHSA
GHSA-98x5-vq43-vc5pCritical
3mo ago

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin

▾ Midnightsemantic-router · semantic-routervia GHSA
GHSA-rhq6-9rgh-v45cMedium· 5.0
3mo ago

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container

Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container

▾ Sunlitpterodactyl · github.com/pterodactyl/wingsvia GHSA
GHSA-j7f5-gfqm-pcx3Medium
3mo ago

Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system

Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system

▾ Sunlitpterodactyl · pterodactyl/panelvia GHSA
GHSA-fhp4-pr5j-46m5High· 7.5
3mo ago

Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key

Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key

▾ Twilightmuhammara · muhammaravia GHSA
CVE-2026-48979High· 7.5
3mo ago

PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling

PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling

▾ Twilightphp-standard-library · php-standard-library/h2EPSS 0.46%via GHSA
GHSA-3p34-w4f6-5xh2High· 7.5
3mo ago

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

▾ Twilightbetter-helperjs · better-helperjsvia GHSA
CVE-2026-48990Medium· 5.3
3mo ago

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

▾ Sunlitjoserfc · joserfcEPSS 0.27%via OSV
CVE-2026-48820Medium
3mo ago

CakePHP: View::element() is missing a path containment check

CakePHP: View::element() is missing a path containment check

▾ Sunlitcakephp · cakephp/cakephpEPSS 0.37%via GHSA
GHSA-q683-8468-r6h6Medium
3mo ago

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

▾ Sunlitweb-auth · web-auth/webauthn-symfony-bundlevia GHSA
GHSA-v2jf-442r-6mjhLow
3mo ago

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

▾ Sunlitjuev · github.com/juev/nebula-meshvia GHSA
GHSA-q6rr-fm2g-g5x8Medium
3mo ago

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx

▾ SunlitScriban · Scribanvia GHSA
GHSA-6q7j-xr26-3h2cMedium
3mo ago

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)

▾ SunlitScriban · Scribanvia GHSA
GHSA-75mw-h36v-2jv7Medium· 6.1
3mo ago

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers

▾ Sunlitdosage · dosagevia GHSA
CVE-2026-49252Critical· 9.9
3mo ago

deepstream is vulnerable to prototype pollution

deepstream is vulnerable to prototype pollution

▾ Midnightdeepstream · @deepstream/serverEPSS 0.47%via GHSA
CVE-2026-49291High· 8.1
3mo ago

mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call

mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call

▾ Twilightmcp-memory-service · mcp-memory-serviceEPSS 0.49%via GHSA
CVE-2026-49454Critical· 9.1
3mo ago

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

▾ Midnightrelyra · relyraEPSS 0.23%via GHSA
CVE-2026-49257Critical· 10.0
3mo ago

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind

▾ Midnightmcp-pinot-server · mcp-pinot-serverEPSS 0.93%via GHSA
GHSA-rp72-5v5q-2446Low
3mo ago

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url

▾ Sunlitcardano402 · @cardano402/mcp-servervia GHSA
GHSA-985r-q3qp-299hHigh· 8.1
3mo ago

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards

▾ Twilightthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-49258High· 8.8
3mo ago

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
CVE-2026-49260High· 8.2
3mo ago

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.22%via GHSA
CVE-2026-5222Low
3mo ago

Cargo can be coerced to share credentials between registries

Cargo can be coerced to share credentials between registries

▾ Sunlitcargo · cargoEPSS 0.50%via GHSA
CVE-2026-5223Medium
3mo ago

Cargo crates in third party registries can override the cached source of other crates

Cargo crates in third party registries can override the cached source of other crates

▾ Sunlitcargo · cargoEPSS 0.41%via GHSA
CVEs tagged “ghsa” — page 92 · VulnSea