IndexedVerified
Config/YAML Security
Generic, YAML, shell, Dockerfile, and CI configuration SAST rules aggregated across verified providers.
Fetch pack
greprules pack fetch config-security --engine opengrepcurl https://api.greprules.io/api/packs/config-security.tar.gz -o config-security.tar.gzIncluded rules
CVE-2026-49129: Curl Meson Build Cwe 918 Cve 2026 49129
cve-2026-49129-curl-meson-build-cwe-918-cve-2026-49129CVE-2026-48962: Perl Unsafe Eval Stringcve-2026-48962-perl-unsafe-eval-stringCVE-2026-48961: Io Compress Zipdetails Typo Unpackvalueqcve-2026-48961-io-compress-zipdetails-typo-unpackvalueqCVE-2026-47744: Livewire Password Get Leakcve-2026-47744-livewire-password-get-leakCVE-2026-47249: Vulnerable Libp2p Dependencycve-2026-47249-vulnerable-libp2p-dependencyCVE-2026-47167: Generic Ruby Eval Regex Injectioncve-2026-47167-generic-ruby-eval-regex-injectionCVE-2026-46740: Adapter Statsd Pm Cwe 000 Cve 2026 46740cve-2026-46740-adapter-statsd-pm-cwe-000-cve-2026-46740CVE-2026-46719: Perl Net Statsd Lite Metric Injectioncve-2026-46719-perl-net-statsd-lite-metric-injectionCVE-2026-46368: Openwrt Rpcd Init Command Injectioncve-2026-46368-openwrt-rpcd-init-command-injectionCVE-2026-45346: Svelte Unsanitized Html Directive Xsscve-2026-45346-svelte-unsanitized-html-directive-xssCVE-2026-45318: Open Webui Excel To Table Unsanitized Html Assignmentcve-2026-45318-open-webui-excel-to-table-unsanitized-html-assignmentCVE-2026-45179: Middleware Statsd Pm Cwe 000 Cve 2026 45179cve-2026-45179-middleware-statsd-pm-cwe-000-cve-2026-45179CVE-2026-44895: Github Actions Publish Missing Event Type Guardcve-2026-44895-github-actions-publish-missing-event-type-guardCVE-2026-44679: Github Actions Unsafe Input Interpolationcve-2026-44679-github-actions-unsafe-input-interpolationCVE-2026-44549: Xlsx Sheet To Html Stored Xsscve-2026-44549-xlsx-sheet-to-html-stored-xssCVE-2026-42302: Code Server Auth None Unauthenticated Rcecve-2026-42302-code-server-auth-none-unauthenticated-rceCVE-2026-41431: Mozconfig Unverified Updates Enabledcve-2026-41431-mozconfig-unverified-updates-enabledCVE-2026-41163: Prctl Set Dumpable Unconditionalcve-2026-41163-prctl-set-dumpable-unconditionalCVE-2026-40906: Elixir Permissive Validator Catchall Okcve-2026-40906-elixir-permissive-validator-catchall-okCVE-2026-40325: Cfml Unvalidated Table Name Settercve-2026-40325-cfml-unvalidated-table-name-setterCVE-2026-35507: Insecure App Json Allowed Hostscve-2026-35507-insecure-app-json-allowed-hostsCVE-2026-34841: Gha Npm Publish Static Secret Token Authcve-2026-34841-gha-npm-publish-static-secret-token-authCVE-2026-34444: Lupa Luaruntime Attribute Filter Without Register Builtins Falsecve-2026-34444-lupa-luaruntime-attribute-filter-without-register-builtins-falseCVE-2026-34243: Github Actions Untrusted Context In Runcve-2026-34243-github-actions-untrusted-context-in-run24 of 93 loaded