Search CVE reports
171 – 180 of 42176 results
Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many...
1 affected package
tinyproxy
| Package | 22.04 LTS |
|---|---|
| tinyproxy | Needs evaluation |
Not in release
Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript...
1 affected package
shaarli
| Package | 22.04 LTS |
|---|---|
| shaarli | Not in release |
Not in release
Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the Bookmark Description field. An authenticated...
1 affected package
shaarli
| Package | 22.04 LTS |
|---|---|
| shaarli | Not in release |
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without...
1 affected package
starlette
| Package | 22.04 LTS |
|---|---|
| starlette | Needs evaluation |
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound...
1 affected package
starlette
| Package | 22.04 LTS |
|---|---|
| starlette | Needs evaluation |
Not in release
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store,...
1 affected package
node-undici
| Package | 22.04 LTS |
|---|---|
| node-undici | Not in release |
Not in release
Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 ยง5.4 does not specify any...
1 affected package
node-undici
| Package | 22.04 LTS |
|---|---|
| node-undici | Not in release |
Not in release
Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or...
1 affected package
node-undici
| Package | 22.04 LTS |
|---|---|
| node-undici | Not in release |
Not in release
Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected...
1 affected package
node-undici
| Package | 22.04 LTS |
|---|---|
| node-undici | Not in release |
Not in release
Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a...
1 affected package
node-undici
| Package | 22.04 LTS |
|---|---|
| node-undici | Not in release |