Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-vgrc-hq28-p3xpHigh· 7.4Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
GHSA-qh5x-rfwf-rvfvHigh· 7.5Hysteria vulnerable to server crash when max_datagram_frame_size very small
Hysteria vulnerable to server crash when max_datagram_frame_size very small
GHSA-jqc5-2p7q-fqfcHigh· 7.5Hysteria: http large header with sniff cause server DoS
Hysteria: http large header with sniff cause server DoS
GHSA-72w7-mf9g-733pMedium· 6.4nono-py has proxy-only network fallback bypass on older Linux kernels
nono-py has proxy-only network fallback bypass on older Linux kernels
CVE-2026-48797CriticalBackpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
GHSA-9j7f-3r4p-pwh6Medium· 5.2nono-py vulnerable to authorization bypass / policy confusion
nono-py vulnerable to authorization bypass / policy confusion
GHSA-m8j6-rc5x-wv36Medium· 5.2nono-py's policy JSON accepts unknown security fields
nono-py's policy JSON accepts unknown security fields
GHSA-98x5-vq43-vc5pCriticalsemantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
GHSA-rhq6-9rgh-v45cMedium· 5.0Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
GHSA-j7f5-gfqm-pcx3MediumPterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
GHSA-fhp4-pr5j-46m5High· 7.5Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key
Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key
CVE-2026-48979High· 7.5PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
GHSA-3p34-w4f6-5xh2High· 7.5better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
CVE-2026-48990Medium· 5.3joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
CVE-2026-48820MediumCakePHP: View::element() is missing a path containment check
CakePHP: View::element() is missing a path containment check
GHSA-q683-8468-r6h6MediumWebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs
GHSA-v2jf-442r-6mjhLownebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction
GHSA-q6rr-fm2g-g5x8MediumScriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
GHSA-6q7j-xr26-3h2cMediumScriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
GHSA-75mw-h36v-2jv7Medium· 6.1Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
CVE-2026-49252Critical· 9.9deepstream is vulnerable to prototype pollution
deepstream is vulnerable to prototype pollution
CVE-2026-49291High· 8.1mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
CVE-2026-49454Critical· 9.1Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
CVE-2026-49257Critical· 10.0mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
GHSA-rp72-5v5q-2446Low@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
GHSA-985r-q3qp-299hHigh· 8.1phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 — editUser() and updateUserRights() lack authorization guards
CVE-2026-49258High· 8.8Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
CVE-2026-49260High· 8.2php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
CVE-2026-5222LowCargo can be coerced to share credentials between registries
Cargo can be coerced to share credentials between registries
CVE-2026-5223MediumCargo crates in third party registries can override the cached source of other crates
Cargo crates in third party registries can override the cached source of other crates