Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 660— Search: GHSA×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 7.8
datamodel-code-generator Code Injection via GraphQL Union Carriage Returns (GHSA-884-q54q-mmx3)
github.com · 2026-07-29

### Vulnerability Overview - **Vulnerability Type**: Code Injection - **Vulnerability Source**: GraphQL union descriptions contain carriage returns ### Impact Scope - **Affected Version**: 0.60.1 - **…

Read more
CVSS 7.5
find-my-way HTTP/2 DoS Vulnerability (GHSA-c96f-x56v-gq3h) and Fix
github.com · 2026-07-29

### Vulnerability Overview - **Vulnerability Name**: DDoS with HTTP2 - **Vulnerability ID**: GHSA-c96f-x56v-gq3h - **Severity**: High (7.5 / 10) - **CVSS v3 Base Metrics**: - Attack Vector: Network - …

Read more
CVSS 7.3
GHSA-grpc-p53c-r64v: @fastify/rate-limit IPv6 Rate Limit Bypass Vulnerability
github.com · 2026-07-30

### Vulnerability Overview - **Vulnerability Name**: `@fastify/rate-limit` has a vulnerability where rate limiting can be bypassed by rotating IPv6 addresses - **Vulnerability ID**: GHSA-grpc-p53c-r64…

Read more
CVSS 7.5
OliveTin Multiple Vulnerabilities Advisory (GHSA)
github.com · 2026-07-30

### Vulnerability Overview Multiple security vulnerabilities were identified in OliveTin version 3000.17.0, primarily involving logging, hardcoded execution, parameter type safety, and OAuth2 state ma…

Read more
CVSS 6.8
Project Capsule: Cross-tenant Privilege Escalation and DoS Vulnerability Fix (GHSA)
github.com · 2026-07-31

### Vulnerability Overview - **GHSA-jp6p-8pjj-mfn6**: Incomplete fix for CVE-2026-22872. `TenantResource` `RawItems` and `Generators` still allow cross-tenant privilege escalation (without impersonati…

Read more
CVSS 7.5
ComfyUI Path Traversal Vulnerability (GHSA-pj99-g9vw-74q4) Analysis and Patch
github.com · 2026-07-31

### Vulnerability Overview - **Vulnerability Name**: Path traversal in `/experiment/models/preview` allows arbitrary image file read - **Vulnerability ID**: GHSA-pj99-g9vw-74q4 - **Severity**: High (7…

Read more
CVSS 8.2
acme-redirect pre-auth heap overflow analysis (GHSA-m37x-9gf5-889p)
github.com · 2026-08-01

### Vulnerability Overview - **Vulnerability Name**: fix: reject ACME requests via signed return #1965 - **Vulnerability Type**: Heap overflow caused by an unterminated path - **Vulnerability Descript…

Read more
CVSS 8.2
Coturn 4.15.0 Multiple Vulnerabilities Fixed (GHSA-5538-7cxj-5jcc/Buffer Overflow/Info Leak)
github.com · 2026-08-01

### Vulnerability Overview Coturn version 4.15.0 addresses multiple security vulnerabilities, primarily including: 1. **STUN Attribute Processing Vulnerability**: STUN attributes following `MESSAGE-IN…

Read more
CVSS 8.5
Decidim v0.31.5 Release Notes: Multiple CVE/GHSA Vulnerability Fixes
github.com · 2026-08-01

### Vulnerability Overview The webpage screenshot displays the release notes for Decidim v0.31.5, which include fixes for multiple security vulnerabilities. These vulnerabilities are associated with s…

Read more
CVSS 6.9
wp-graphql v2.15.1 User Enumeration Vulnerability via SendPasswordResetEmail (GHSA-jhh7-832h-88hy)
github.com · 2026-08-01

### Vulnerability Overview A user enumeration vulnerability was identified in `wp-graphql` version 2.15.1. This vulnerability exists in the `SendPasswordResetEmail` mutation, specifically within the `…

Read more
CVSS 3.1
Sigstore sigstore-go GHSA-wqpc-jqc-vxhm Signature Time Window Validation Fix
github.com · 2026-08-01

### Vulnerability Overview - **Vulnerability ID**: GHSA-wqpc-jqc-vxhm - **Description**: Window issue for checking signature time and public key validity. ### Affected Scope - **Version**: v1.2.1 ### …

Read more
CVSS 6.1
GHSA-vmhf-c436-hxj4: Stored XSS in JupyterLab Extension Manager via PyPI Metadata
github.com · 2026-08-01

### Vulnerability Overview - **Vulnerability Name**: Stored XSS in extension manager through package metadata unsanitized URI protocol - **Vulnerability ID**: GHSA-vmhf-c436-hxj4 - **Release Date**: J…

Read more
Premium intel
CVSS 9.8
Database SQL Engine Bypass via DEFINE FUNCTION LANGUAGE js (GHSA-48qw)
github.com · 2026-08-01

### Vulnerability Overview - **Vulnerability Name**: Scripting authorization gate (GHSA-48qw) bypassed via SQL `DEFINE FUNCTION ... LANGUAGE js` - **Vulnerability Description**: The mitigation for GHS…

Read more
CVSS 4.3
OrientDB RBAC Bypass: Low-Priv User Schema Mutation via Missing Check in GHSA-8vr5-263f-xdr3
github.com · 2026-08-01

### Vulnerability Overview - **Vulnerability Name**: Read-only users can mutate type schema via ALTER TYPE CUSTOM and BUCKETSELECTIONSTRATEGY (missing UPDATE_SCHEMA check, sibling gap of GHSA-vg6x/GHS…

Read more
CVSS 6.9
GHSA-xqch-r77q-rgf5: atom-table DoS in ueberauth/guardian via unbounded String.to_atom
github.com · 2026-08-02

# Vulnerability Overview - **Vulnerability Name**: Unbounded atom creation from binary input (atom-table DoS) - **Vulnerability ID**: GHSA-xqch-r77q-rgf5 - **Vulnerability Description**: Guardian Plug…

Read more
CVSS 5.3
libiec61850 MMS Server RptID Oversized Invalid Free Vulnerability (GHSA-7ggb-hm25-rv0v)
github.com · 2026-08-03

### Vulnerability Overview - **Vulnerability Name**: MMS server: fixed - oversized RptID written to RCB can trigger invalid free when reports are sent later - **Vulnerability Description**: In the MMS…

Read more
Premium intel
CVSS 8.8
Angular SSR HttpTransferCache Cache-Key Ambiguity Leading to State Poisoning (GHSA-jhpw-976m-542)
github.com · 2026-08-04

### Vulnerability Overview **Vulnerability Name**: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning **Vulnerability ID**: GHSA-jhpw-976m-542 **Sever…

Read more
CVSS 7.5
brace-expansion DoS Bypass GHSA-mh99-v99m-4gyv: Unbounded Arrays and Memory Exhaustion
github.com · 2026-08-04

### Vulnerability Overview **Title**: DoS via unbounded intermediate arrays, bypassing the GHSA-mh99-v99m-4gyv mitigation **Description**: - **Summary**: The fix for `maxLength` added in version 5.0.8…

Read more
CVSS 6.5
GHSA: Tool List API Leaks Source Code with Hardcoded Credentials to Read-Only Users (CVE-2026-70491)
github.com · 2026-08-05

# Vulnerability Overview - **Vulnerability Title**: Tool source code disclosed to read-only users via the tool list and get endpoints - **Vulnerability ID**: GHSA-3r7g-q5cq-q2vx - **Severity**: 6.5 / …

Read more
CVSS 5.3
Mermaid CSS Injection Affecting Sibling DOM Elements (GHSA-67f9-hmwm-qbdp)
github.com · 2026-08-07

### Vulnerability Overview Mermaid allows CSS injection to affect sibling elements of the chart. Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors have the `mermaid-X…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.