Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-pr64-jmmf-jp54
  • Go/github.com/stacklok/toolhive
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) 13 hours ago
  • Fix available
  • Severity - 2.9 (Low)
GHSA-ggw3-5987-rx77
  • Go/github.com/pomerium/pomerium
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-74j5-xf3v-crq8
  • Go/github.com/DataDog/dd-trace-go
  • Go/github.com/DataDog/dd-trace-go/v2
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-398h-7f66-3h4p
  • Go/github.com/open-feature/open-feature-operator
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters 14 hours ago
  • No fix available
  • Severity - 4.3 (Medium)
GHSA-xgch-x3mx-cm3c
  • Go/github.com/doyensec/safeurl
safeurl is Missing IPv6 CIDR Ranges in Blocklist 15 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-pph6-vfjv-vpjw
  • Go/github.com/stacklok/toolhive
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway 15 hours ago
  • Fix available
  • Severity - 2.9 (Low)
GHSA-qf34-295c-26v8
  • Go/github.com/woodpecker-ci/woodpecker
  • Go/go.woodpecker-ci.org/woodpecker/v2
  • Go/go.woodpecker-ci.org/woodpecker/v3
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend yesterday
  • Fix available
  • Severity - 8.2 (High)
GHSA-7rx3-5wx3-5v76
  • Go/github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` yesterday
  • Fix available
  • Severity - 7.7 (High)
GHSA-cm26-5974-52h8
  • Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Certificate revocation is never enforced at the mesh yesterday
  • Fix available
  • Severity - 8.1 (High)
GHSA-g4x6-jcvr-9m3g
  • Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens yesterday
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-m3cx-mwpg-32jg
  • Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-mf78-3rpf-r784
  • Go/github.com/julien040/anyquery
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode yesterday
  • No fix available
  • Severity - 7.5 (High)
GHSA-q4vm-pq3q-8wgq
  • Go/github.com/forgekeep/nebula-mesh
nebula-mesh: Operator session tokens stored in plaintext in the database yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-2p2f-px33-4vv5
  • Go/github.com/forgekeep/nebula-mesh
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths yesterday
  • Fix available
  • Severity - 8.7 (High)
GHSA-hwrq-8wxh-q4xv
  • Go/github.com/julien040/anyquery
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode yesterday
  • No fix available
  • Severity - 8.6 (High)
GHSA-mqxv-9rm6-w8qc
  • Go/github.com/lin-snow/ech0
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware yesterday
  • No fix available
  • Severity - 8.7 (High)