GitHub Security Advisories (GHSA) are authoritative notices for vulnerable open-source packages and ecosystems (for example npm, PyPI, or Maven), usually with a linked CVE. Use the search box to find a GHSA or CVE, narrow by ecosystem or severity, or match phrases in the summary.
| GHSA | CVE | Severity | Type | Summary | Published |
|---|---|---|---|---|---|
| GHSA-gvjc-3w7c-92jx | CVE-2026-52737 | medium | reviewed | Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block | 2026-07-02 19:44:24 UTC |
| GHSA-gf9r-m956-97qx | CVE-2026-52735 | critical | reviewed | zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser | 2026-07-02 19:43:36 UTC |
| GHSA-4m69-67m6-prqp | CVE-2026-52736 | high | reviewed | Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache | 2026-07-02 19:43:08 UTC |
| GHSA-h72h-ppcx-998p | — | low | reviewed | Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length | 2026-07-02 19:42:05 UTC |
| GHSA-4fc2-h7jh-287c | CVE-2026-52732 | medium | reviewed | zebrad has mempool transaction admission denial via single-peer inbound queue saturation | 2026-07-02 19:39:02 UTC |
| GHSA-c8w6-x74f-vmg3 | — | medium | reviewed | zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers | 2026-07-02 19:37:58 UTC |
| GHSA-443g-gwgp-49x4 | — | low | reviewed | zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length | 2026-07-02 19:34:21 UTC |
| GHSA-qv2r-v3mx-f4pf | CVE-2026-52731 | medium | reviewed | zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate | 2026-07-02 19:28:03 UTC |
| GHSA-77q5-rr5v-x43q | — | high | reviewed | OpenClaw: Trusted retry endpoint checks could match hostname prefixes | 2026-07-02 17:22:11 UTC |
| GHSA-3rjw-m598-pq24 | CVE-2026-50185 | medium | reviewed | Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set | 2026-07-02 17:18:11 UTC |
| GHSA-qjpc-qf9m-xwmr | — | high | reviewed | OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing | 2026-07-02 16:43:53 UTC |
| GHSA-rggc-m335-3wvj | — | high | reviewed | OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers | 2026-07-02 16:03:10 UTC |
| GHSA-2vg7-9fw4-fmph | CVE-2026-56037 | high | unreviewed | Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection.... | 2026-07-02 12:31:00 UTC |
| GHSA-vxwx-6665-hvwh | CVE-2026-14428 | high | unreviewed | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0... | 2026-07-02 00:31:42 UTC |
| GHSA-9v66-88c9-pqcg | CVE-2026-14429 | high | unreviewed | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46... | 2026-07-02 00:31:42 UTC |
| GHSA-2wv3-7v49-h6mj | CVE-2026-14414 | medium | unreviewed | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46... | 2026-07-02 00:31:42 UTC |
| GHSA-gm8p-g47w-pwgf | CVE-2026-14412 | high | unreviewed | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46... | 2026-07-02 00:31:41 UTC |
| GHSA-8jr8-cv4x-4jmv | CVE-2026-14411 | critical | unreviewed | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46... | 2026-07-02 00:31:41 UTC |
| GHSA-7fh8-qj6w-5vcc | CVE-2026-14382 | critical | unreviewed | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46... | 2026-07-02 00:31:41 UTC |
| GHSA-3x3p-qx4r-hmgh | CVE-2026-14401 | high | unreviewed | Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0... | 2026-07-02 00:31:41 UTC |