Skip to content

The catalog

Browse GHSA Reproductions

80 verified reproductions

RSS Feed

80 reproductions

Clear filters
Active GHSA
REPRO-2026-00283 published

Nuclio cron trigger shell command injection leading to RCE

CVE-2026-52831 critical Security Variant found go
github.com/nuclio/nuclio
89m 0s Jul 11, 2026
REPRO-2026-00274 published

@better-auth/sso <1.6.11 allows non-blind SSRF via unvalidated OIDC endpoint URLs during SSO provider registration, with potential account takeover when trustEmailVerified is enabled.

CVE-2026-53513 critical Security Variant found npm
@better-auth/sso
30m 49s Jul 8, 2026
REPRO-2026-00273 published

Vtiger CRM through 8.4.0 allows authenticated admin users to achieve remote code execution by uploading a crafted module ZIP that places PHP files in the web-accessible modules/ directory.

CVE-2026-23698 high Security Variant found other
Vtiger CRM
33m 54s Jul 8, 2026
REPRO-2026-00272 published

EGroupware contains an authorization bypass in SmallPartMediaRecorder::ajax_upload combined with arbitrary file write and file read primitives, enabling authenticated (or self-registered) attackers to overwrite header.inc.php and achieve remote code execution.

CVE-2026-27823 critical Security Variant found Composer
egroupware/egroupware
78m 4s Jul 8, 2026
REPRO-2026-00271 published

Apache Airflow <3.3.0 allows deserialization of attacker-controlled class paths in BaseSerialization.deserialize(), enabling DAG authors to trigger RCE in the Scheduler/API Server via malicious serialized DAGs.

CVE-2026-33264 critical Security Variant found PyPI
apache/airflow
34m 38s Jul 8, 2026
REPRO-2026-00264 published

Apache Camel camel-docling improperly validates custom CLI arguments, enabling argument injection and path traversal when untrusted data is mapped into docling invocation headers.

CVE-2026-40047 critical Security Variant found Maven
apache/camel
41m 23s Jul 7, 2026
REPRO-2026-00186 published

libssh2 via curl: malformed SSH packet length crashes SFTP client

CVE-2026-55200 critical Security c
libssh2
11m 23s Jun 25, 2026
REPRO-2026-00185 published

HashiCorp Nomad: path traversal in host volume plugin loader → client-host RCE

CVE-2026-7474 high Security Variant found go
nomad
48m 9s May 28, 2026
REPRO-2026-00183 published

MapServer: heap-buffer-overflow in SLD Categorize parser (msSLDParseRasterSymbolizer)

CVE-2026-33721 medium Security Variant found c
mapserver
14m 33s May 28, 2026
REPRO-2026-00170 published

jq: integer overflow in jv_string_concat triggers heap buffer overflow on large strings

CVE-2026-32316 high Security Variant found github
jq
32m 33s May 28, 2026
REPRO-2026-00159 published

libheif: heap-buffer-overflow write decoding 1x4 grid of odd-height tiles

CVE-2026-32740 high Security Variant found c
libheif
41m 53s May 23, 2026
REPRO-2026-00158 published

goshs: PUT upload accepts cross-origin requests without CSRF token

CVE-2026-42091 medium Security Variant found go
github.com/patrickhener/goshs
35m 17s May 23, 2026
REPRO-2026-00157 published

Fiber v3: cache middleware key collision leaks responses across different query strings

CVE-2026-30246 medium Security Variant found go
github.com/gofiber/fiber/v3
27m 11s May 23, 2026
REPRO-2026-00156 published

Yii2: local file inclusion via View::renderPhpFile extract() of caller-controlled params

CVE-2026-39850 high Security Variant found composer
yiisoft/yii2
15m 11s May 23, 2026
REPRO-2026-00155 published

gitoxide (gix-fs): symlink worktree escape on checkout writes files outside the worktree

CVE-2026-44471 high Security Variant found cargo
gix-fs
33m 22s May 22, 2026
REPRO-2026-00153 published

Jupyter Server: path traversal via faulty startswith() root containment check

CVE-2026-35397 high Security Variant found pip
jupyter-server
25m 14s May 22, 2026
REPRO-2026-00152 published

apko: symlink-following path traversal writes files outside the build root

CVE-2026-42574 high Security Variant found go
apko
20m 23s May 22, 2026
REPRO-2026-00151 published

Twig: sandbox bypass via SourcePolicy filter check enables arbitrary PHP callables

CVE-2026-24425 high Security Variant found composer
twig/twig
13m 7s May 22, 2026
REPRO-2026-00150 published

PhpSpreadsheet: SSRF via unsafe stream wrapper in IOFactory::load()

CVE-2026-34084 critical Security Variant found composer
phpoffice/phpspreadsheet
12m 53s May 22, 2026
REPRO-2026-00149 published

PraisonAI: ZipSlip path traversal via unchecked tar symlink linkname in _safe_extractall

CVE-2026-44340 high Security Variant found pip
praisonai
17m 42s May 22, 2026