Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-54515Medium· 5.3PoCjackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)
A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…
CVE-2026-54516Medium· 5.3jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security controls by exploiting an issue in how properties are handled when both @JsonProperty (for renaming) and @JsonIgnore (for ignoring) annota…
CVE-2026-54517Medium· 5.3jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)
A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…
CVE-2026-48126High· 8.2Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
CVE-2026-48157Medium· 6.1Slim has Reflected XSS in the HtmlErrorRenderer
Slim has Reflected XSS in the HtmlErrorRenderer
CVE-2026-48166Medium· 5.3Filament: Timing-based user enumeration on login page
Filament: Timing-based user enumeration on login page
CVE-2026-48167Medium· 6.4Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
CVE-2026-48480MediumOHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
CVE-2026-48488LowphpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
CVE-2026-48492MediumSnipe-IT's selectlist visibility is too permissive
Snipe-IT's selectlist visibility is too permissive
CVE-2026-48493Medium· 5.5Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
CVE-2026-48500Medium· 6.5Filament: Unauthenticated temporary file upload on auth pages
Filament: Unauthenticated temporary file upload on auth pages
GHSA-wcmj-x466-56mmMedium· 6.1OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
CVE-2026-48507High· 7.1Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
CVE-2026-49205Medium· 6.5phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
GHSA-w2j7-f3c6-g8cwMedium· 4.7Flask-Security has an Open Redirect issue
Flask-Security has an Open Redirect issue
CVE-2026-55542LowSnipe-IT's S3 signature image retrieval lacks authorization before temporary URL
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
CVE-2026-54329High· 8.5Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
CVE-2026-8823Low· 3.8Mattermost has an Incorrect Authorization issue
Mattermost has an Incorrect Authorization issue
CVE-2026-56104High· 7.4Chainlit contains a session hijacking vulnerability
Chainlit contains a session hijacking vulnerability
CVE-2026-12249Critical· 9.0Canonical ADSys Uses a Less Trusted Source
Canonical ADSys Uses a Less Trusted Source
CVE-2026-6673Medium· 6.4Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
CVE-2026-6062Medium· 6.4Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-9162Medium· 4.3Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
CVE-2026-8074Low· 3.8Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-5139Medium· 5.4Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-44913Medium· 7.2Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
CVE-2026-54665Medium· 5.3Apache NiFi fails to validate proxy host headers when constructing qualified URLs
Apache NiFi fails to validate proxy host headers when constructing qualified URLs
CVE-2026-44911LowApache NiFi allows read-only users to submit component configuration verification request
Apache NiFi allows read-only users to submit component configuration verification request
CVE-2025-66336High· 8.1Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path
Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path