Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MGASA-2026-0463
  • Mageia:10/python-pillow
Updated python-pillow packages fix security vulnerabilities 42 minutes ago
  • Fix available
RLSA-2026:73519
  • Rocky Linux:8/rubygem-abrt
  • Rocky Linux:8/rubygem-bson
  • Rocky Linux:8/rubygem-bundler
  • Rocky Linux:8/rubygem-mysql2
  • Rocky Linux:8/rubygem-pg
Important: ruby:2.5 security update 46 minutes ago
  • Fix available
  • Severity - 8.3 (High)
RLSA-2026:74085
  • Rocky Linux:8/nodejs-nodemon
  • Rocky Linux:8/nodejs-packaging
Important: nodejs:24 security, bug fix, and enhancement update 50 minutes ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-94p9-xgh2-xp45
  • PyPI/virtualenv
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use 57 minutes ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-9h9j-4vrj-gf7g
  • PyPI/virtualenv
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection 57 minutes ago
  • Fix available
  • Severity - 5.8 (Medium)
GHSA-4mh8-r7rc-xpvc
  • npm/fastify
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses 57 minutes ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-gvp8-978c-rx2q
  • PyPI/pyjwt
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse 58 minutes ago
  • No fix available
  • Severity - 6.5 (Medium)
GHSA-3hv7-mjh2-fv65
  • PyPI/tornado
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS 1 hour ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-chx6-46f5-w4vp
  • PyPI/tornado
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-c2m8-h5v5-343r
  • PyPI/tornado
Tornado: StaticFileHandler follows symlinks outside static root (path traversal) 1 hour ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-59cr-6r3x-644w
  • PyPI/gitpython
GitPython submodule update path traversal can write outside the repository 1 hour ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-hxh3-vqpv-xpqv
  • npm/hono
hono/jsx renders plain strings unescaped in boundary components, leading to XSS 1 hour ago
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-667r-xxjv-c9mm
  • npm/fastify
fastify vulnerable to request body replacement via an async validation result collision 1 hour ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-p68q-wchp-6fh7
  • npm/fastify
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-hwr6-493r-vm6h
  • npm/fastify
fastify vulnerable to request validation bypass via skipped boolean false schemas 1 hour ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-9q9j-q6p8-xq58
  • npm/fastify
fastify vulnerable to header validation bypass via incomplete schema case normalization 1 hour ago
  • Fix available
  • Severity - 7.5 (High)