24h | 7d | 30d

Overview

  • Apache Software Foundation
  • Apache Commons IO
  • commons-io:commons-io

03 Oct 2024
Published
31 Jan 2025
Updated

CVSS
Pending
EPSS
1.32%

KEV

Description

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Pending

02 Oct 2022
Published
03 Aug 2024
Updated

CVSS
Pending
EPSS
3.41%

KEV

Description

In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net/http
  • net/http

28 Jan 2025
Published
18 Sep 2025
Updated

CVSS
Pending
EPSS
0.67%

KEV

Description

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net/http
  • net/http

12 Mar 2025
Published
16 Apr 2026
Updated

CVSS
Pending
EPSS
0.40%

KEV

Description

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • net/url
  • net/url

29 Oct 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.47%

KEV

Description

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: "http://[::1]/". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go toolchain
  • cmd/go
  • cmd/go

29 Jul 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.42%

KEV

Description

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Pending

02 Oct 2022
Published
03 Aug 2024
Updated

CVSS
Pending
EPSS
3.41%

KEV

Description

In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • os
  • os

04 Feb 2026
Published
05 Feb 2026
Updated

CVSS
Pending
EPSS
0.25%

KEV

Description

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • os/exec
  • os/exec

18 Sep 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.55%

KEV

Description

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Go standard library
  • syscall
  • syscall

11 Jun 2025
Published
11 Jun 2025
Updated

CVSS
Pending
EPSS
0.31%

KEV

Description

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 3h ago
Showing 121 to 130 of 185 CVEs