VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.3CVE-2026-11417aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
- HIGH7.5Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
- LOW3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
- HIGH7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
- LOW3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
- LOW3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
- LOW3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
- HIGH7.7Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- HIGH7.5tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- HIGH7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- HIGH8.2protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
- LOW3.1React Router: Potential CSRF via PUT/PATCH/DELETE document requests
- HIGH7.5protobufjs: Denial of service through unbounded Any expansion during JSON conversion
- LOW3.2@babel/core: Arbitrary File Read via sourceMappingURL Comment
- HIGH8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
- HIGH7.5ws: Memory exhaustion DoS from tiny fragments and data chunks
- HIGH7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
- HIGH7.5Netty: Wrapping plain trust manager silently disables hostname verification
- HIGH7.5Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
- HIGH7.5form-data: CRLF injection in form-data via unescaped multipart field names and filenames
- LOW3.7Tornado has out-of-bounds memory access via C extension
- HIGH8.1Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
- HIGH7.5Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
- HIGH7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
- HIGH7.7Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection