Open Source Vulnerabilities
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
linux-nvidia-6.17
linux-nvidia-6.17 vulnerabilities
Traefik: ForwardAuth identity spoofing via dot-form header alias
Traefik: ForwardAuth identity spoofing via dot-form header alias
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 Path Traversal via code.find MCP tool
knowns through 0.33.0 Path Traversal via code.find MCP tool
knowns through 0.33.0 Path Traversal via Template Engine
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
cilium-fips-1.19-operator-generic
n8n, n8n, n8n
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n/ n8n/ n8n
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n, n8n, n8n
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n/ n8n/ n8n
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n, n8n
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n/ n8n
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n, n8n, n8n
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
n8n/ n8n/ n8n
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
ua-parser-js, @rootio/ua-parser-js
CVE-2022-25927 in ua-parser-js - Patched by Root
ua-parser-js/ @rootio/ua-parser-js
CVE-2022-25927 in ua-parser-js - Patched by Root
open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
github.com/xuri/excelize/v2, github.com/xuri/excelize
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
github.com/xuri/excelize/v2/ github.com/xuri/excelize
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
github.com/xuri/excelize/v2, github.com/xuri/excelize
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
github.com/xuri/excelize/v2/ github.com/xuri/excelize
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
@koa/cors, koajs_cors
TuxCare security update for 2 packages (2 CVEs)
@koa/cors/ koajs_cors
TuxCare security update for 2 packages (2 CVEs)
@eigenpal/docx-editor-core, @eigenpal/docx-editor-react
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
@eigenpal/docx-editor-core/ @eigenpal/docx-editor-react
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
nodemailer
TuxCare security update for nodemailer (6 CVEs)
nodemailer
TuxCare security update for nodemailer (6 CVEs)
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
cilium-fips-1.19-operator-azure
datadog-agent-7.76, datadog-agent-7.76
code.gitea.io/gitea
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
code.gitea.io/gitea
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
code.gitea.io/gitea
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
code.gitea.io/gitea
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
code.gitea.io/gitea
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
code.gitea.io/gitea
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
code.gitea.io/gitea
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
code.gitea.io/gitea
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
code.gitea.io/gitea
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
code.gitea.io/gitea
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
github.com/siyuan-note/siyuan/kernel
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
github.com/siyuan-note/siyuan/kernel
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
