The catalog
Browse GHSA Reproductions
84 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00338 Apache Log4j2 serialized LogEvent filter bypass to conditional RCE REPRO-2026-00340 PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 unauthenticated RCE chain REPRO-2026-00327 Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection (swatchrc dosnmp Perl backtick) REPRO-2026-00343 Jenkins XStream deserialization of nested PersistenceRoot objects leads to RCE via Stapler (SECURITY-3972)
84 reproductions
Clear filters Active GHSA
REPRO-2026-00339 published
bubblewrap: sandbox escape via /oldroot symlink traversal during setup — files created on host
GHSA-PXHW-H44J-8PFX high Security Known vulnerability
bubblewrap
18m 28s Aug 26, 2026
REPRO-2026-00338 published
Apache Log4j2 serialized LogEvent filter bypass to conditional RCE
GHSA-LOG4J2-4255-MARSHALLEDOBJECT critical Security Known vulnerability maven
org.apache.logging.log4j:log4j-core
73m 31s Aug 26, 2026
REPRO-2026-00296 published
Reported Horilla protected_media Referer authentication bypass
GHSA-9WJX-4J4R-FF8W high Security
Variant found
Known vulnerability github
horilla/horilla-hr
77m 9s Jul 26, 2026
REPRO-2026-00295 published
Horilla HRMS protected_media path traversal enables outside-root file read
GHSA-x52c-5hrq-76pq high Security
Variant found
Known vulnerability github
horilla/horilla-hr
87m 3s Jul 25, 2026
REPRO-2026-00283 published
Nuclio cron trigger shell command injection leading to RCE
CVE-2026-52831 critical Security
Variant found
go
github.com/nuclio/nuclio
89m 0s Jul 11, 2026
REPRO-2026-00274 published
@better-auth/sso <1.6.11 allows non-blind SSRF via unvalidated OIDC endpoint URLs during SSO provider registration, with potential account takeover when trustEmailVerified is enabled.
CVE-2026-53513 critical Security
Variant found
npm
@better-auth/sso
30m 49s Jul 8, 2026
REPRO-2026-00273 published
Vtiger CRM through 8.4.0 allows authenticated admin users to achieve remote code execution by uploading a crafted module ZIP that places PHP files in the web-accessible modules/ directory.
CVE-2026-23698 high Security
Variant found
other
Vtiger CRM
33m 54s Jul 8, 2026
REPRO-2026-00272 published
EGroupware contains an authorization bypass in SmallPartMediaRecorder::ajax_upload combined with arbitrary file write and file read primitives, enabling authenticated (or self-registered) attackers to overwrite header.inc.php and achieve remote code execution.
CVE-2026-27823 critical Security
Variant found
Composer
egroupware/egroupware
78m 4s Jul 8, 2026
REPRO-2026-00271 published
Apache Airflow <3.3.0 allows deserialization of attacker-controlled class paths in BaseSerialization.deserialize(), enabling DAG authors to trigger RCE in the Scheduler/API Server via malicious serialized DAGs.
CVE-2026-33264 critical Security
Variant found
PyPI
apache/airflow
34m 38s Jul 8, 2026
REPRO-2026-00264 published
Apache Camel camel-docling improperly validates custom CLI arguments, enabling argument injection and path traversal when untrusted data is mapped into docling invocation headers.
CVE-2026-40047 critical Security
Variant found
Maven
apache/camel
41m 23s Jul 7, 2026
REPRO-2026-00186 published
libssh2 via curl: malformed SSH packet length crashes SFTP client
CVE-2026-55200 critical Security c
libssh2
11m 23s Jun 25, 2026
REPRO-2026-00185 published
HashiCorp Nomad: path traversal in host volume plugin loader → client-host RCE
CVE-2026-7474 high Security
Variant found
go
nomad
48m 9s May 28, 2026
REPRO-2026-00183 published
MapServer: heap-buffer-overflow in SLD Categorize parser (msSLDParseRasterSymbolizer)
CVE-2026-33721 medium Security
Variant found
c
mapserver
14m 33s May 28, 2026
REPRO-2026-00170 published
jq: integer overflow in jv_string_concat triggers heap buffer overflow on large strings
CVE-2026-32316 high Security
Variant found
github
jq
32m 33s May 28, 2026
REPRO-2026-00159 published
libheif: heap-buffer-overflow write decoding 1x4 grid of odd-height tiles
CVE-2026-32740 high Security
Variant found
c
libheif
41m 53s May 23, 2026
REPRO-2026-00158 published
goshs: PUT upload accepts cross-origin requests without CSRF token
CVE-2026-42091 medium Security
Variant found
go
github.com/patrickhener/goshs
35m 17s May 23, 2026
REPRO-2026-00157 published
Fiber v3: cache middleware key collision leaks responses across different query strings
CVE-2026-30246 medium Security
Variant found
go
github.com/gofiber/fiber/v3
27m 11s May 23, 2026
REPRO-2026-00156 published
Yii2: local file inclusion via View::renderPhpFile extract() of caller-controlled params
CVE-2026-39850 high Security
Variant found
composer
yiisoft/yii2
15m 11s May 23, 2026
REPRO-2026-00155 published
gitoxide (gix-fs): symlink worktree escape on checkout writes files outside the worktree
CVE-2026-44471 high Security
Variant found
cargo
gix-fs
33m 22s May 22, 2026
REPRO-2026-00153 published
Jupyter Server: path traversal via faulty startswith() root containment check
CVE-2026-35397 high Security
Variant found
pip
jupyter-server
25m 14s May 22, 2026