Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-52804MediumGogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
CVE-2026-52805High· 8.7Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
CVE-2026-52806Critical· 9.9PoCGogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge
CVE-2026-52807HighGogs has DOM-based XSS via Milestone Name on New Issue Page
Gogs has DOM-based XSS via Milestone Name on New Issue Page
CVE-2026-52808High· 7.1Gogs's write-level collaborators can mutate admin-only repository settings via API
Gogs's write-level collaborators can mutate admin-only repository settings via API
CVE-2026-52809Medium· 6.8Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
CVE-2026-52810HighPoCGogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
CVE-2026-52811CriticalGogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
CVE-2026-52812HighGogs: LFS dedupe path leaks private repo content across tenants
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-52813Critical· 10.0PoCGogs has Path Traversal in organization name that results in RCE through Git hooks
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52814MediumGogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
CVE-2026-52815MediumPoCGogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
CVE-2026-45049High· 8.3OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet
OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet
CVE-2026-52816MediumGogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
CVE-2026-55173High· 8.1AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
CVE-2026-54350Critical· 10.0PoCBudibase has nonymous NoSQL operator injection via published-app query templates
Budibase has nonymous NoSQL operator injection via published-app query templates
CVE-2026-53925High· 7.8Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
CVE-2026-54134HighOctoPrint has possible file exfiltration via query parameters on upload endpoints
OctoPrint has possible file exfiltration via query parameters on upload endpoints
CVE-2026-54557Medium· 5.5mise HTTP backend uses raw version path for install symlink destination
mise HTTP backend uses raw version path for install symlink destination
CVE-2026-55441High· 8.6Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
CVE-2026-55448Medium· 6.3Mise's local credential_command executes untrusted config
Mise's local credential_command executes untrusted config
CVE-2026-55488HighmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
GHSA-phv5-334h-mxcwCriticalmotionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
GHSA-7cqp-7cfv-6c3qMediumAVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel
AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel
CVE-2026-54518Medium· 6.5jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass (CVE-2026-54518)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…
CVE-2026-50193High· 7.5jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)
A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor. A remote attacker can exploit this vulnerability by sending deeply nested JSON (JavaScript Object Notation) data to a service that rea…
CVE-2026-54512High· 8.1PoCjackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…
CVE-2026-54513High· 8.1jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)
A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…
CVE-2026-54514Medium· 5.3jackson-databind: jackson-databind: Information Disclosure via Eager DNS Resolution (CVE-2026-54514)
A flaw was found in jackson-databind, a library used for processing JSON data. This vulnerability allows a remote attacker to force the application to perform an attacker-chosen DNS (Domain Name System) query. This occurs when untrusted JS…