Skip to content

The catalog

Browse GHSA Reproductions

82 verified reproductions

RSS Feed

82 reproductions

Clear filters
Active GHSA
REPRO-2026-00090 published

WinRAR ADS Path Traversal — Arbitrary Code Execution via Crafted Archive (CVE-2025-8088)

CVE-2025-8088 high Security
123m 42s Feb 17, 2026
REPRO-2026-00089 published

pyca/cryptography SECT curve public key parsing lacks subgroup validation, enabling small-subgroup attacks that leak ECDH private key bits and allow ECDSA signature forgery.

CVE-2026-26007 medium Security Variant found
cryptography (pip)
6m 32s Feb 15, 2026
REPRO-2026-00088 published

Sliver has DNS C2 OTP Bypass that Allows Unauthenticated Session Flooding and Denial of Service

GHSA-WXRW-GVG8-FQJP Security Variant found
13m 22s Feb 13, 2026
REPRO-2026-00087 published

Apache Druid basic security LDAP authenticator can be bypassed when the LDAP server allows anonymous binds, permitting login with any existing username and an empty password.

CVE-2026-23906 critical Security Variant found Maven
org.apache.druid.extensions:druid-basic-security
48m 55s Feb 13, 2026
REPRO-2026-00085 published

Pillow 10.3.0–12.1.0 allows an out-of-bounds write when loading specially crafted PSD images, potentially leading to memory corruption.

GHSA-CFH3-3JMP-RVHC Security Variant found
3m 16s Feb 13, 2026
REPRO-2026-00084 published

Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

CVE-2025-64712 critical Security Variant found pypi
unstructured
4m 50s Feb 13, 2026
REPRO-2026-00080 published

Docling-core YAML Deserialization RCE via FullLoader

CVE-2026-24009 high Security Variant found pip
docling-core
6m 1s Feb 13, 2026
REPRO-2026-00078 published

vLLM RCE via auto_map dynamic module loading

CVE-2026-22807 high Security pip
vllm
19m 50s Jan 22, 2026
REPRO-2026-00076 published

MCP Server Git: Path Traversal via Missing Repository Path Validation

CVE-2025-68145 critical Security pip
mcp-server-git
11m 29s Jan 21, 2026
REPRO-2026-00070 published

wlc: Path traversal via unsanitized API slugs in download command

CVE-2026-23535 high Security pip
wlc
20m 59s Jan 17, 2026
REPRO-2026-00067 published

Svelte XSS via textarea bind:value in SSR

GHSA-gw32-9rmw-qwww high Security npm
svelte
8m 49s Jan 17, 2026
REPRO-2026-00066 published

Skipper Lua Filter Arbitrary Code Execution

GHSA-cc8m-98fm-rc9g high Security go
github.com/zalando/skipper
9m 5s Jan 17, 2026
REPRO-2026-00065 published

node-tar Arbitrary File Overwrite via Hardlink Escape

GHSA-8qq5-rm4j-mr97 high Security npm
tar
6m 8s Jan 17, 2026
REPRO-2026-00064 published

node-tar Arbitrary File Overwrite via Hardlink Escape

GHSA-8qq5-rm4j-mr97 high Security npm
tar
6m 8s Jan 17, 2026
REPRO-2026-00063 published

deepdiff: Class Pollution RCE via Delta Tuple Path Bypass

CVE-2025-58367 critical Security pip
deepdiff
1m 7s Jan 13, 2026
REPRO-2026-00062 published

langgraph-checkpoint: Constructor Deserialization RCE in JsonPlusSerializer

CVE-2025-64439 high Security pip
langgraph-checkpoint
1m 7s Jan 12, 2026
REPRO-2026-00061 published

python-socketio: Pickle Deserialization RCE in PubSub Manager

CVE-2025-61765 medium Security pip
python-socketio
1m 5s Jan 12, 2026
REPRO-2026-00054 published

Craft CMS: Unauthenticated Database Backup Trigger

CVE-2025-68456 critical Security composer
craftcms/cms
36m 45s Jan 8, 2026
REPRO-2026-00052 published

ComfyUI-Manager: Configuration File Exposure via Web-Accessible Path

CVE-2025-67303 high Security pip
ComfyUI-Manager
11m 32s Jan 8, 2026
REPRO-2026-00045 published

BentoML RCE via Insecure Deserialization

CVE-2025-27520 critical Security pip
bentoml
16m 37s Jan 7, 2026