Nim-lang

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 11
    Known Exploited: 0
    2
    Critical Level Threats
    5
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-46872

    An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum 2.2.0 is fixed.)

    Last Modified: Apr 07, 2025
    Published: Jan 13, 2023

    CVE-2022-23602

    Nim's rst parser sandboxed mode allows include which can embed any local file

    Last Modified: May 05, 2025
    Published: Feb 01, 2022

    CVE-2020-23171

    A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.

    Last Modified: Nov 21, 2024
    Published: Aug 10, 2021

    CVE-2021-29495

    Nim stdlib httpClient does not validate peer certificates by default

    Last Modified: Nov 21, 2024
    Published: May 07, 2021

    CVE-2021-21373

    Nimble falls back to insecure http url when fetching packages

    Last Modified: Nov 21, 2024
    Published: Mar 26, 2021
    Items Per Page
    Nim-Lang Vulnerabilities & Security CVEs | CVE-DB