VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.5CVE-2026-49855tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- HIGH7.5CVE-2026-48818Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- MEDIUM5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
- —aiohttp: Incomplete websocket frame payloads bypass memory limits
- —aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
- —aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
- —aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
- —aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
- —aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
- —aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
- —aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
- —aiohttp: CRLF injection in multipart headers
- MEDIUM6.9Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
- HIGH7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
- HIGH7.5Netty: Wrapping plain trust manager silently disables hostname verification
- HIGH7.5Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
- MEDIUM4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
- MEDIUM5.3Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
- LOW3.7Tornado has out-of-bounds memory access via C extension
- MEDIUM6.5GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
- HIGH7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
- HIGH7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
- HIGH7.1WsgiDAV encoded dot segments can escape filesystem share roots
- —Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
- MEDIUM5.8Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset