VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.3CVE-2026-11417aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
- MEDIUM5.3markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
- HIGH7.5Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
- MEDIUM5.3OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
- LOW3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
- —Nest: Middleware Bypass on Fastify via Trailing Slash
- HIGH7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
- LOW3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
- LOW3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
- LOW3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
- —Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
- HIGH7.7Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- HIGH7.5tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- HIGH7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- MEDIUM5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
- MEDIUM5.3UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
- HIGH8.2protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
- MEDIUM5.3protobufjs: Memory amplification from preserved unknown fields in binary decode
- —aiohttp: Incomplete websocket frame payloads bypass memory limits
- —aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
- —aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
- —aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
- —aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
- —aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
- —aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges