Published issues
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away
Permalink
CVE-2026-13593
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away
Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
Permalink
CVE-2026-13601
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
2 packages
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
Stack-Based Buffer Overflow in libxml2
Permalink
CVE-2026-11979
1.8 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Active (A)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Active (A)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
9 packages
- libxml2Python
- sbclPackages.cl-libxml2
- perlPackages.AlienLibxml2
- python312Packages.libxml2
- python313Packages.libxml2
- python314Packages.libxml2
- perl5Packages.AlienLibxml2
- perl538Packages.AlienLibxml2
- perl540Packages.AlienLibxml2
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Stack-Based Buffer Overflow in libxml2
Spice-vdagent: path traversal in file transfer via unsanitized filename
Permalink
CVE-2026-57966
4.4 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Spice-vdagent: path traversal in file transfer via unsanitized filename
spice-vdagent
mingw-spice-vdagent
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
Permalink
CVE-2026-58050
8.3 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
2 packages
- haskellPackages.libssh2
- haskellPackages.libssh2-conduit
4 weeks, 1 day ago
-
@LeSuisse
ignored
2 references
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
Permalink
CVE-2026-58051
8.3 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
2 packages
- haskellPackages.libssh2
- haskellPackages.libssh2-conduit
4 weeks, 1 day ago
-
@LeSuisse
ignored
reference src/publi…
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
perlPackages.JavaScriptMinifierXS: security issues < 0.16
Permalink
CVE-2026-56018
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth
Permalink
CVE-2026-56017
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash
cherry-studio: security issues <= 1.9.9
Permalink
CVE-2026-13534
1.3 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
4 references
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
cherry-studio
-
==1.9.5
-
==1.9.7
-
==1.9.3
-
==1.9.4
-
==1.9.0
-
==1.9.2
-
==1.9.6
-
==1.9.1
Permalink
CVE-2026-13524
2.9 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
4 references
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
cherry-studio
-
==1.9.5
-
==1.9.3
-
==1.9.4
-
==1.9.0
-
==1.9.2
-
==1.9.6
-
==1.9.1
gzip: security issues <= 1.14
Permalink
CVE-2026-41992
6.9 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
8 packages
- rapidgzip
- ocamlPackages.ezgzip
- minimal-bootstrap.gzip
- perlPackages.PerlIOgzip
- perl5Packages.PerlIOgzip
- perl538Packages.PerlIOgzip
- perl540Packages.PerlIOgzip
- ocamlPackages_latest.ezgzip
4 weeks, 1 day ago
-
@LeSuisse
ignored
reference https://w…
4 weeks, 1 day ago
-
@LeSuisse
ignored
8 packages
- python312Packages.rapidgzip
- python313Packages.rapidgzip
- python314Packages.rapidgzip
- minimal-bootstrap.gzip-static
- python312Packages.indexed-gzip
- python313Packages.indexed-gzip
- python314Packages.indexed-gzip
- haskellPackages.hack-middleware-gzip
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Global Buffer Overflow in GNU gzip
Permalink
CVE-2026-41991
2.0 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
reference https://w…
4 weeks, 1 day ago
-
@LeSuisse
ignored
16 packages
- rapidgzip
- ocamlPackages.ezgzip
- minimal-bootstrap.gzip
- perlPackages.PerlIOgzip
- perl5Packages.PerlIOgzip
- perl538Packages.PerlIOgzip
- perl540Packages.PerlIOgzip
- ocamlPackages_latest.ezgzip
- python312Packages.rapidgzip
- python313Packages.rapidgzip
- python314Packages.rapidgzip
- minimal-bootstrap.gzip-static
- python312Packages.indexed-gzip
- python313Packages.indexed-gzip
- python314Packages.indexed-gzip
- haskellPackages.hack-middleware-gzip
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Predictable Temporary File in GNU gzip
skypilot-org skypilot User ID server.py username.encode weak hash
Permalink
CVE-2026-13482
2.9 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): POC (P)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
1 month ago
by @LeSuisse
Activity log
-
Created suggestion
1 month ago
-
@LeSuisse
ignored
4 references
1 month ago
-
@LeSuisse
accepted
1 month ago
-
@LeSuisse
published on GitHub
1 month ago
skypilot-org skypilot User ID server.py username.encode weak hash
skypilot
-
==0.12.0
-
==0.4
-
==0.7
-
==0.1
-
==0.10
-
==0.6
-
==0.2
-
==0.5
-
==0.11
-
==0.8
-
==0.9
-
==0.3