Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Security Intel Hub 354— Search: GHSA×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
GHSA-243v-98vx-264h: Wasmtime WASI HTTP DoS Vulnerability
github.com · 2026-02-25

### Critical Vulnerability Information #### Vulnerability Overview - **Vulnerability ID**: GHSA-243v-98vx-264h - **CVE ID**: CVE-2026-27572 - **Severity**: Medium (CVSS v4 base score: 6.9/10) #### Imp…

Read more
CVSS 7.7
GHSA-jcc6-f9v6-f7jw: Authenticated Full Read SSRF via Favicon Fetching (CVE-2026-27706)
github.com · 2026-02-26

### Key Information #### Vulnerability Details - **Title**: Full Read SSRF via Favicon Fetching in "Add Link" Feature - **ID**: GHSA-jcc6-f9v6-f7jw - **Publisher**: sriramveeraghanta - **Published**: …

Read more
CVSS 5.3
Rucio WebUI Username Enumeration via Login Error Message (GHSA-38wq-6q2w-hcf9)
github.com · 2026-02-26

### Key Information #### Vulnerability Title - Username Enumeration via Login Error Message in Rucio WebUI #### Vulnerability ID - GHSA-38wq-6q2w-hcf9 #### Severity - Moderate (5.3/10) #### Affected V…

Read more
CVSS 7.1
Zed Editor Agent File Tools Symlink Escape Vulnerability (GHSA-786m-xzvc-5235)
github.com · 2026-02-26

### Key Vulnerability Information #### Vulnerability Title - **Symlink Escape in Agent File Tools** #### Vulnerability ID - GHSA-786m-xzvc-5235 #### Publisher and Time - swannysec, published 2 hours a…

Read more
CVSS 7.7
GHSA-4q9f-mjxf-rx7x: wp-graphql Workflow Expression Injection Fix
github.com · 2026-02-26

### Critical Vulnerability Information #### Vulnerability Description - **Vulnerability ID**: GHSA-4q9f-mjxf-rx7x - **Type**: Expression Injection - **Affected Scope**: wp-graphql/v2.9.1 and earlier v…

Read more
CVSS 4.8
GHSA-8c9r-pvrj-vcf5: Audiobookshelf Stored XSS Vulnerability
github.com · 2026-02-26

### Key Information #### Vulnerability Overview - **Vulnerability Type**: Stored XSS - **ID**: GHSA-8c9r-pvrj-vcf5 - **Affected Component**: assets/WrappingMarquee.js - **Affected Versions**: `; - Cha…

Read more
Path Traversal in Hex.pm Local File Store Backend (GHSA-42mv-r64p-4869)
github.com · 2026-02-27

### Vulnerability Key Information #### Basic Information - **Title**: Path Traversal in Local File Store Backend (Development and Self-Hosted Registry Setups) - **Publisher**: maennchen - **Published*…

Read more
Premium intel
CVSS 8.6
ZimaOS GHSA-65mg-9gw5 Unauthorized File Creation via API Bypass
github.com · 2026-03-03

## Critical Vulnerability Information ### Vulnerability Overview - **Vulnerability Name**: ZimaOS v1.5.2-beta3 - Unauthorized Creation of Files/Folders in Restricted System Directories via API - **Vul…

Read more
CVSS 8.8
XSS Fix Patch and GHSA-hc3c-8p55-xh4r Advisory
github.com · 2026-03-03

**Vulnerability Information in the Screenshot:** - **Commit Description**: - The commit message indicates that this change is to "Apply XSS removal when importing users." This suggests that prior code…

Read more
Sulu CMS Security Fix Advisory (GHSA-6h7h-m7p5-hjgq)
github.com · 2026-04-02

## Vulnerability Key Information ### Vulnerability Overview - **Vulnerability ID**: GHSA-6h7h-m7p5-hjgq - **Type**: Security fix - **Fixed by**: @alexander-schranz - **Acknowledgments**: @sh4dowalker …

Read more
KEV
Telnyx Python Package Supply Chain Poisoning (GHSA-953r-262c-63c5) and Malware Analysis
github.com · 2026-04-02

# Telnyx Python Package Malicious Code Vulnerability (GHSA-953r-262c-63c5) ## Vulnerability Overview - **Date**: March 27, 2025 - **Attacker**: Exploited leaked PyPI credentials to directly upload mal…

Read more
CVSS 7.1
TinaCMS Symlink Bypass Leading to Path Traversal (GHSA-gB7r-2gJ3-J9Sw)
github.com · 2026-04-02

## Vulnerability Overview **Vulnerability Type**: Symlink/Path Traversal Bypass **Vulnerability IDs**: GHSA-gB7r-2gJ3-J9Sw, GHSA-gB2r-p725-3x07 **Core Issue**: The path validation in TinaCMS's media e…

Read more
Parse Server LiveQuery Protected Field Guard Bypass (GHSA-mmg8-87c5-jrc2)
github.com · 2026-04-02

## Vulnerability Key Information Summary ### Vulnerability Overview - **Vulnerability Name**: LiveQuery protected-field guard bypass via array-like logical operator value - **CVE/GHSA ID**: GHSA-mmg8-…

Read more
parse-server GHSA-f6j3-w9v3-cq22 Session Field Immutability Bypass Vulnerability
github.com · 2026-04-02

## Vulnerability Key Information Summary ### Vulnerability Overview - **Vulnerability Name**: Session field immutability bypass via falsy-value guard - **CVE/GHSA ID**: GHSA-f6j3-w9v3-cq22 - **Vulnera…

Read more
Parse Server LiveQuery Protected-Field Guard Bypass (GHSA-mmg8-87c5-jrc2)
github.com · 2026-04-02

## Vulnerability Key Information Summary ### Vulnerability Overview - **Vulnerability Name**: LiveQuery protected-field guard bypass via array-like logical operator value - **CVE/GHSA ID**: GHSA-mmg8-…

Read more
Parse Server Cloud Function Validator Bypass via Prototype Chain Traversal (GHSA-vpj2-qq7w-5qq6)
github.com · 2026-04-02

## Vulnerability Key Information Summary ### Vulnerability Overview | Item | Content | |:---|:---| | **Vulnerability Name** | Cloud function validator bypass via prototype chain traversal | | **Vulner…

Read more
Parse Server GraphQL Query Complexity Validator DoS via Exponential Fragment Traversal (GHSA-mf3j-6cp4-m98c)
github.com · 2026-04-02

## Vulnerability Overview **Vulnerability Type**: GraphQL Query Complexity Validator Exponential Fragment Traversal Denial of Service (DoS) **CVE ID**: GHSA-mf3j-6cp4-m98c **Description**: Parse Serve…

Read more
Parse Server /verifyPassword MFA Secret Leakage Vulnerability (GHSA-wp7p-gg32-8258)
github.com · 2026-04-02

## Vulnerability Overview **Vulnerability ID**: GHSA-wp7p-gg32-8258 **Issue**: The `/verifyPassword` endpoint in Parse Server contains an **authentication data leakage vulnerability**. When multi-fact…

Read more
Parse Server GraphQL Complexity Validator DoS via Fragment Fan-out (GHSA-mf9j-6p94-m8bc)
github.com · 2026-04-02

## Vulnerability Overview **Vulnerability Type**: GraphQL Complexity Validator Exponential Fragment Traversal Denial of Service (DoS) **CVE ID**: GHSA-mf9j-6p94-m8bc, GHSA-mfj8-dp5d-m8bc **Description…

Read more
Parse Server MFA One-Time Token Bypass via Race Condition (GHSA-w73w-g5sw-rw9f)
github.com · 2026-04-02

## Vulnerability Summary ### Vulnerability Overview **MFA Single-Use Token Bypass via Concurrent authData Login Requests** ([GHSA-w73w-g5sw-rw9f]) This vulnerability allows attackers to bypass the MFA…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.