Search CVE reports
1 – 10 of 42038 results
h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...
1 affected package
python-h2
| Package | 24.04 LTS |
|---|---|
| python-h2 | Needs evaluation |
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end...
1 affected package
node-re2
| Package | 24.04 LTS |
|---|---|
| node-re2 | Needs evaluation |
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior...
1 affected package
jsoup
| Package | 24.04 LTS |
|---|---|
| jsoup | Needs evaluation |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several...
2 affected packages
commonmark, markdown
| Package | 24.04 LTS |
|---|---|
| commonmark | Needs evaluation |
| markdown | Needs evaluation |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab,...
2 affected packages
commonmark, markdown
| Package | 24.04 LTS |
|---|---|
| commonmark | Needs evaluation |
| markdown | Needs evaluation |
Not in release
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can...
1 affected package
node-mermaid
| Package | 24.04 LTS |
|---|---|
| node-mermaid | Not in release |
Not in release
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig,...
1 affected package
node-mermaid
| Package | 24.04 LTS |
|---|---|
| node-mermaid | Not in release |
Not in release
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines...
1 affected package
node-mermaid
| Package | 24.04 LTS |
|---|---|
| node-mermaid | Not in release |
Not in release
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the...
1 affected package
node-mermaid
| Package | 24.04 LTS |
|---|---|
| node-mermaid | Not in release |
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty...
1 affected package
node-re2
| Package | 24.04 LTS |
|---|---|
| node-re2 | Needs evaluation |