VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-48995Medium
3mo ago

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

▾ Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-49357High
3mo ago

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

▾ Twilightline-desktop-mcp · line-desktop-mcpEPSS 0.56%via GHSA
CVE-2026-47066High
3mo ago

Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry

Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-47071High
3mo ago

Hackney: `ssl:connect/2` post-handshake upgrade has no timeout

Hackney: `ssl:connect/2` post-handshake upgrade has no timeout

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-47076Medium
3mo ago

Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host

Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host

▾ Sunlithackney · hackneyEPSS 0.16%via GHSA
CVE-2026-47069Low
3mo ago

Hackney has CRLF / header injection via unvalidated `domain` and `path` options

Hackney has CRLF / header injection via unvalidated `domain` and `path` options

▾ Sunlithackney · hackneyEPSS 0.36%via GHSA
CVE-2026-47070Medium
3mo ago

Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body

Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body

▾ Sunlithackney · hackneyEPSS 0.35%via GHSA
CVE-2026-47074High
3mo ago

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM

▾ Twilighthackney · hackneyEPSS 0.38%via GHSA
CVE-2026-47075Medium
3mo ago

Hackney has CR/LF injection in query parameter

Hackney has CR/LF injection in query parameter

▾ Sunlithackney · hackneyEPSS 0.42%via GHSA
CVE-2026-47072Medium
3mo ago

Hackney has CRLF / header injection in WebSocket upgrade request

Hackney has CRLF / header injection in WebSocket upgrade request

▾ Sunlithackney · hackneyEPSS 0.52%via GHSA
CVE-2026-47073High
3mo ago

Hackney has unbounded buffer accumulation in WebSocket

Hackney has unbounded buffer accumulation in WebSocket

▾ Twilighthackney · hackneyEPSS 0.82%via GHSA
CVE-2026-47067High
3mo ago

Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes

Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes

▾ Twilighthackney · hackneyEPSS 0.70%via GHSA
CVE-2026-49286High· 8.1
3mo ago

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)

▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.95%via GHSA
CVE-2026-49358Low· 3.0
3mo ago

PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles

PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles

▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.15%via GHSA
CVE-2026-49359Medium· 6.5
3mo ago

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option

▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.42%via GHSA
CVE-2026-49288Medium· 4.3
3mo ago

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources

▾ Sunlitstatamic · statamic/cmsEPSS 0.27%via GHSA
CVE-2026-49287High· 7.4
3mo ago

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

▾ Twilightstatamic · statamic/cmsEPSS 0.46%via GHSA
GHSA-7vfx-4246-jcfhHigh
3mo ago

SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings

SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings

▾ Twilightsolidinvoice · solidinvoice/solidinvoicevia GHSA
CVE-2026-49293High· 7.5
3mo ago

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

▾ Twilightjs-toml · js-tomlEPSS 0.64%via GHSA
CVE-2026-49336Medium
3mo ago

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

▾ Sunlitmicrosoft · @microsoft/kiota-http-fetchlibraryEPSS 1.2%via GHSA
CVE-2026-49342Medium· 5.3
3mo ago

YARD static cache reads raw traversal paths before router sanitization

YARD static cache reads raw traversal paths before router sanitization

▾ Sunlityard · yardEPSS 0.40%via GHSA
GHSA-wcr3-9x4c-f5gjHigh
3mo ago

Blnk has an API key authorization bypass in owner and scope enforcement

Blnk has an API key authorization bypass in owner and scope enforcement

▾ Twilightblnkfinance · github.com/blnkfinance/blnkvia GHSA
GHSA-q6xx-5vr8-p898Critical· 9.9
3mo ago

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

▾ Midnightnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-48794Low
3mo ago

Authelia has an Edge Case Access Control Rule Mismatch

Authelia has an Edge Case Access Control Rule Mismatch

▾ Sunlitauthelia · github.com/authelia/authelia/v4EPSS 0.41%via GHSA
GHSA-8jgf-23q5-x7xxHigh
3mo ago

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass

▾ Twilightex_aws_sns · ex_aws_snsvia GHSA
CVE-2026-50573Medium· 6.8
3mo ago

pnpm: Unsafe default behavior breaks integrity check

pnpm: Unsafe default behavior breaks integrity check

▾ Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-50021Medium· 6.8
3mo ago

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

▾ Sunlitpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-50014Medium· 6.4
3mo ago

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

▾ Sunlitpnpm · pnpmEPSS 0.32%via GHSA
CVE-2026-50016High· 8.8
3mo ago

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

▾ Twilightpnpm · pnpmEPSS 0.53%via GHSA
CVE-2026-50017Medium
3mo ago

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

▾ Sunlitpnpm · pnpmEPSS 0.44%via GHSA
CVEs tagged “ghsa” — page 93 · VulnSea