The catalog
Browse GHSA Reproductions
80 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00294 WordPress 7.0.1 pre-auth fresh-administrator chain to RCE REPRO-2026-00281 Apache Kafka SASL/OAUTHBEARER accepts unvalidated JWTs REPRO-2026-00293 Metabase arbitrary code execution via unsafe H2 connection property validation bypass REPRO-2026-00222 SimpleHelp OIDC authentication accepts unsigned/forged ID tokens, enabling remote authentication bypass and possible MFA bypass in versions 5.5.15 and earlier and 6.0 prereleases prior to the fixed release. REPRO-2026-00259 iCagenda unauthenticated file upload RCE in public event submission form REPRO-2026-00223 phpBB authentication bypass/account hijacking via OAuth login-link flow with arbitrary auth_provider=apache
80 reproductions
Clear filters Active GHSA
REPRO-2026-00148 published
Mistune: ReDoS via catastrophic backtracking in LINK_TITLE_RE
CVE-2026-33079 high Security
Variant found
pip
mistune
14m 50s May 22, 2026
REPRO-2026-00147 published
Faraday: SSRF via protocol-relative URL overriding base authority
CVE-2026-25765 medium Security
Variant found
rubygems
faraday
10m 15s May 22, 2026
REPRO-2026-00146 published
fast-uri: host confusion via percent-encoded authority delimiter in normalize()
CVE-2026-6322 high Security
Variant found
npm
fast-uri
10m 18s May 22, 2026
REPRO-2026-00145 published
fast-uri: path traversal via percent-encoded segments decoded before normalization
CVE-2026-6321 high Security
Variant found
npm
fast-uri
10m 8s May 22, 2026
REPRO-2026-00144 published
phpMyFAQ: unauthenticated SQL injection via User-Agent header in captcha API
CVE-2026-46364 critical Security
Variant found
composer
thorsten/phpmyfaq
62m 14s May 22, 2026
REPRO-2026-00143 published
@wdio/browserstack-service: OS command injection via crafted git branch name
CVE-2026-25244 critical Security
Variant found
npm
@wdio/browserstack-service
59m 49s May 22, 2026
REPRO-2026-00142 published
libheif: integer underflow out-of-bounds read crash via crafted HEIF stsc box
CVE-2026-32738 medium Security
Variant found
c
libheif
50m 30s May 22, 2026
REPRO-2026-00139 published
libjwt: JWT algorithm-confusion authentication bypass via RSA JWK without alg
CVE-2026-44699 critical Security
Variant found
c
libjwt
13m 26s May 22, 2026
REPRO-2026-00138 published
FastMCP: path traversal to authenticated SSRF in OpenAPIProvider _build_url()
CVE-2026-32871 critical Security
Variant found
pip
fastmcp
37m 15s May 22, 2026
REPRO-2026-00136 published
Microsoft APM: arbitrary file disclosure via symlink-following on apm install
CVE-2026-45539 high Security
Variant found
pip
apm
29m 1s May 22, 2026
REPRO-2026-00134 published
lodash: prototype pollution in _.unset/_.omit deletes global prototype methods
CVE-2025-13465 medium Security
Variant found
npm
lodash
29m 27s May 22, 2026
REPRO-2026-00124 published
Vim modeline handling for the tabpanel option allows sandbox escape via autocmd_add, enabling OS command execution when opening a crafted file.
CVE-2026-34714 critical Security
Variant found
github
Vim
19m 38s Apr 1, 2026
REPRO-2026-00119 published
PyTorch: weights_only Unpickler RCE via SETITEM Type Confusion
CVE-2026-24747 high Security
Variant found
pip
torch
48m 8s Mar 2, 2026
REPRO-2026-00115 published
eBay MCP Server Environment Variable Injection via Crafted Prompts
CVE-2026-27203 high Security npm
@anthropic-ai/ebay-mcp-server
11m 39s Feb 20, 2026
REPRO-2026-00114 published
D-Tale Remote Code Execution via Custom Filter Input
CVE-2026-27194 critical Security pip
dtale
11m 53s Feb 20, 2026
REPRO-2026-00113 published
Feathers OAuth Authorization Header Leak to Third-Party
CVE-2026-27192 high Security npm
@feathersjs/authentication-oauth
7m 45s Feb 20, 2026
REPRO-2026-00112 published
Statamic CMS Stored XSS via Markdown Fieldtype
CVE-2026-27197 critical Security composer
statamic/cms
7m 48s Feb 20, 2026
REPRO-2026-00111 published
Formwork CMS Improper Privilege Management in User Creation
CVE-2026-27198 high Security composer
getformwork/formwork
12m 42s Feb 20, 2026
REPRO-2026-00110 published
Deno Command Injection via Incomplete Metacharacter Blocklist
CVE-2026-27190 high Security rust
deno
10m 5s Feb 20, 2026
REPRO-2026-00109 published
Feathers OAuth Open Redirect Account Takeover
CVE-2026-27191 medium Security npm
@feathersjs/authentication-oauth
12m 54s Feb 20, 2026