VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-jf6w-2mvx-633jMedium· 6.1
3mo ago

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

▾ Sunlitjusthtml · justhtmlvia GHSA
GHSA-wrr4-782v-jhwhLow
3mo ago

neotoma has tenant isolation gap in relationship query endpoints

neotoma has tenant isolation gap in relationship query endpoints

▾ Sunlitneotoma · neotomavia GHSA
GHSA-fq3w-p4fg-mw73Low
3mo ago

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

▾ Sunlitfixurjavainstall · fixurjavainstallvia GHSA
GHSA-r4v7-6wcg-ghj5Medium· 6.5
3mo ago

FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks

FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks

▾ Sunlitgtsteffaniak · github.com/gtsteffaniak/filebrowservia GHSA
GHSA-rjr7-jggh-pgcpHigh
3mo ago

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-9g5q-2w5x-hmxfHigh
3mo ago

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-3fxj-6jh8-hvhxMedium
3mo ago

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

▾ Sunlitgo-chi · github.com/go-chi/chi/v5/middlewarevia GHSA
CVE-2026-48775Medium· 6.8
3mo ago

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

▾ Sunlitlanggraph-checkpoint · langgraph-checkpointEPSS 0.69%via GHSA
CVE-2026-48776Medium· 4.2
3mo ago

LangGraph SDK has unsafe URL path construction

LangGraph SDK has unsafe URL path construction

▾ Sunlitlanggraph-sdk · langgraph-sdkEPSS 0.29%via GHSA
CVE-2026-9291High· 7.1
3mo ago

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

▾ Twilightamazon-braket-sdk · amazon-braket-sdkEPSS 0.65%via GHSA
CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-48504Medium· 5.3
3mo ago

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

▾ Sunlitopentelemetry_sdk · opentelemetry_sdkEPSS 0.42%via GHSA
CVE-2026-48505High· 7.4
3mo ago

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

▾ Twilightfilament · filament/filamentEPSS 0.30%via GHSA
CVE-2026-48506High· 7.5
3mo ago

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth

▾ TwilightMessagePack · MessagePackEPSS 0.47%via GHSA
CVE-2026-48509Medium
3mo ago

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

▾ SunlitMessagePack · MessagePackEPSS 0.42%via GHSA
CVE-2026-48510Medium· 7.5
3mo ago

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48511Medium· 7.5
3mo ago

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48512Medium
3mo ago

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48513Medium
3mo ago

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48514Medium
3mo ago

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48515Medium
3mo ago

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48516Medium
3mo ago

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings

MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings

▾ SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-48517Medium
3mo ago

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

▾ SunlitMessagePack · MessagePackEPSS 0.35%via GHSA
CVE-2026-48529Medium· 6.0
3mo ago

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

▾ Sunlitgithub · github.com/github/github-mcp-serverEPSS 0.21%via GHSA
CVE-2026-48724Medium· 5.5
3mo ago

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-48733Medium· 4.7
3mo ago

ImageMagick has an Infinite Loop in subimage-search with crafted image

ImageMagick has an Infinite Loop in subimage-search with crafted image

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.12%via GHSA
CVE-2026-48734Medium· 5.5
3mo ago

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2026-48994Medium· 5.9
3mo ago

ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems

ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.37%via GHSA
CVE-2026-49218High· 7.5
3mo ago

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

▾ TwilightMagick · Magick.NET-Q16-AnyCPUEPSS 0.63%via GHSA
CVE-2026-49219Medium· 5.5
3mo ago

ImageMagick: Policy Bypass can read disallowed files via symlink

ImageMagick: Policy Bypass can read disallowed files via symlink

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.17%via GHSA
CVEs tagged “ghsa” — page 95 · VulnSea