Search CVE reports
341 – 350 of 40129 results
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id`...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the...
1 affected package
hugo
| Package | 26.04 LTS |
|---|---|
| hugo | Needs evaluation |
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field,...
1 affected package
python-git
| Package | 26.04 LTS |
|---|---|
| python-git | Needs evaluation |
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |