Search CVE reports
211 – 220 of 39999 results
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field,...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present,...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |