Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-48995Mediumpnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
CVE-2026-49357HighStreamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
CVE-2026-47066HighHackney has an infinite loop on non-token byte at start of an Alt-Svc entry
Hackney has an infinite loop on non-token byte at start of an Alt-Svc entry
CVE-2026-47071HighHackney: `ssl:connect/2` post-handshake upgrade has no timeout
Hackney: `ssl:connect/2` post-handshake upgrade has no timeout
CVE-2026-47076MediumHackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host
Hackney has SSRF allowlist bypass in hackney_url:normalize/2 via percent-encoded host
CVE-2026-47069LowHackney has CRLF / header injection via unvalidated `domain` and `path` options
Hackney has CRLF / header injection via unvalidated `domain` and `path` options
CVE-2026-47070MediumHackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
Hackney: Cross-origin Redirect Leaks Authorization, Cookie, and Request Body
CVE-2026-47074HighHackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
Hackney: Per-chunk timeout with unbounded body accumulation enables slow-drip OOM
CVE-2026-47075MediumHackney has CR/LF injection in query parameter
Hackney has CR/LF injection in query parameter
CVE-2026-47072MediumHackney has CRLF / header injection in WebSocket upgrade request
Hackney has CRLF / header injection in WebSocket upgrade request
CVE-2026-47073HighHackney has unbounded buffer accumulation in WebSocket
Hackney has unbounded buffer accumulation in WebSocket
CVE-2026-47067HighHackney vulnerable to atom-table exhaustion via unrecognized URL schemes
Hackney vulnerable to atom-table exhaustion via unrecognized URL schemes
CVE-2026-49286High· 8.1PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
CVE-2026-49358Low· 3.0PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
CVE-2026-49359Medium· 6.5PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
CVE-2026-49288Medium· 4.3Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
CVE-2026-49287High· 7.4Statamic CMS's unsafe method invocation via collection sorting allows data destruction
Statamic CMS's unsafe method invocation via collection sorting allows data destruction
GHSA-7vfx-4246-jcfhHighSolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
CVE-2026-49293High· 7.5js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
CVE-2026-49336Medium@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
CVE-2026-49342Medium· 5.3YARD static cache reads raw traversal paths before router sanitization
YARD static cache reads raw traversal paths before router sanitization
GHSA-wcr3-9x4c-f5gjHighBlnk has an API key authorization bypass in owner and scope enforcement
Blnk has an API key authorization bypass in owner and scope enforcement
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
CVE-2026-48794LowAuthelia has an Edge Case Access Control Rule Mismatch
Authelia has an Edge Case Access Control Rule Mismatch
GHSA-8jgf-23q5-x7xxHighex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
CVE-2026-50573Medium· 6.8pnpm: Unsafe default behavior breaks integrity check
pnpm: Unsafe default behavior breaks integrity check
CVE-2026-50021Medium· 6.8pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2026-50014Medium· 6.4pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVE-2026-50016High· 8.8pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVE-2026-50017Mediumpnpm binds unscoped user-level npm auth credentials to a repository-selected registry
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry