Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported ngi...
Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration โ unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text
flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into diffe...
Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
Oj: Integer Overflow in Oj.load 2GB String Handling
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking