VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-54515Medium· 5.3PoC
3mo ago

jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)

A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.44%via CSAF
CVE-2026-54516Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security controls by exploiting an issue in how properties are handled when both @JsonProperty (for renaming) and @JsonIgnore (for ignoring) annota…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.45%via CSAF
CVE-2026-54517Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)

A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-48126High· 8.2
3mo ago

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir

▾ Twilightxyproto · github.com/xyproto/algernonEPSS 0.50%via GHSA
CVE-2026-48157Medium· 6.1
3mo ago

Slim has Reflected XSS in the HtmlErrorRenderer

Slim has Reflected XSS in the HtmlErrorRenderer

▾ Sunlitslim · slim/slimEPSS 0.26%via GHSA
CVE-2026-48166Medium· 5.3
3mo ago

Filament: Timing-based user enumeration on login page

Filament: Timing-based user enumeration on login page

▾ Sunlitfilament · filament/filamentEPSS 0.34%via GHSA
CVE-2026-48167Medium· 6.4
3mo ago

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS

▾ Sunlitfilament · filament/infolistsEPSS 0.25%via GHSA
CVE-2026-48480Medium
3mo ago

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttpEPSS 0.27%via GHSA
CVE-2026-48488Low
3mo ago

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing

▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.28%via GHSA
CVE-2026-48492Medium
3mo ago

Snipe-IT's selectlist visibility is too permissive

Snipe-IT's selectlist visibility is too permissive

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.39%via GHSA
CVE-2026-48493Medium· 5.5
3mo ago

Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment

Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.31%via GHSA
CVE-2026-48500Medium· 6.5
3mo ago

Filament: Unauthenticated temporary file upload on auth pages

Filament: Unauthenticated temporary file upload on auth pages

▾ Sunlitfilament · filament/filamentEPSS 0.34%via GHSA
GHSA-wcmj-x466-56mmMedium· 6.1
3mo ago

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree

▾ Sunlitopentofu · github.com/opentofu/opentofuvia GHSA
CVE-2026-48507High· 7.1
3mo ago

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users

▾ Twilightsnipe · snipe/snipe-itEPSS 0.42%via GHSA
CVE-2026-49205Medium· 6.5
3mo ago

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.39%via GHSA
GHSA-w2j7-f3c6-g8cwMedium· 4.7
3mo ago

Flask-Security has an Open Redirect issue

Flask-Security has an Open Redirect issue

▾ SunlitFlask-Security · Flask-Securityvia GHSA
CVE-2026-55542Low
3mo ago

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.28%via GHSA
CVE-2026-54329High· 8.5
3mo ago

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

▾ Twilightsnipe · snipe/snipe-itEPSS 0.39%via GHSA
CVE-2026-8823Low· 3.8
3mo ago

Mattermost has an Incorrect Authorization issue

Mattermost has an Incorrect Authorization issue

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.32%via OSV
CVE-2026-56104High· 7.4
3mo ago

Chainlit contains a session hijacking vulnerability

Chainlit contains a session hijacking vulnerability

▾ Twilightchainlit · chainlitEPSS 0.42%via OSV
CVE-2026-12249Critical· 9.0
3mo ago

Canonical ADSys Uses a Less Trusted Source

Canonical ADSys Uses a Less Trusted Source

▾ Midnightubuntu · github.com/ubuntu/adsysvia OSV
CVE-2026-6673Medium· 6.4
3mo ago

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

▾ Sunlitmattermost · github.com/mattermost/mattermost-servervia OSV
CVE-2026-6062Medium· 6.4
3mo ago

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

▾ Sunlitmattermost · github.com/mattermost/mattermost-servervia OSV
CVE-2026-9162Medium· 4.3
3mo ago

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

▾ Sunlitmattermost · github.com/mattermost/mattermost-servervia OSV
CVE-2026-8074Low· 3.8
3mo ago

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

▾ Sunlitmattermost · github.com/mattermost/mattermost-servervia OSV
CVE-2026-5139Medium· 5.4
3mo ago

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

▾ Sunlitmattermost · github.com/mattermost/mattermost-servervia OSV
CVE-2026-44913Medium· 7.2
3mo ago

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL

▾ Sunlitapache · org.apache.nifi:nifi-cdc-mysql-processorsEPSS 0.65%via GHSA
CVE-2026-54665Medium· 5.3
3mo ago

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

Apache NiFi fails to validate proxy host headers when constructing qualified URLs

▾ Sunlitapache · org.apache.nifi:nifi-jettyEPSS 0.33%via GHSA
CVE-2026-44911Low
3mo ago

Apache NiFi allows read-only users to submit component configuration verification request

Apache NiFi allows read-only users to submit component configuration verification request

▾ Sunlitapache · org.apache.nifi:nifi-web-apiEPSS 0.52%via GHSA
CVE-2025-66336High· 8.1
3mo ago

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

▾ Twilightdoris-mcp-server · doris-mcp-serverEPSS 0.56%via OSV
CVEs tagged “ghsa” — page 99 · VulnSea