The Lab · 2026-04-11 13:22:30 · GitHub Issues
A critical security flaw in the widely-used Axios HTTP client library for Node.js allows attackers to trigger uncontrolled memory consumption and potential denial-of-service attacks. The vulnerability, tracked as CVE-2025-58754, stems from how Axios handles URLs with the `data:` scheme. When processing such a URL, the ...
The Lab · 2026-04-11 14:22:33 · GitHub Issues
A critical security gap in a major cinema ticketing platform's API exposes its servers to memory exhaustion and denial-of-service attacks. The vulnerability stems from a systemic lack of input length validation across core route handlers, allowing attackers to send massive payloads that can cripple system resources. Th...
The Lab · 2026-04-12 10:22:33 · GitHub Issues
A critical vulnerability in the widely-used Axios HTTP client library for Node.js allows attackers to trigger uncontrolled memory consumption, potentially leading to denial-of-service conditions. The flaw, tracked as CVE-2025-58754, resides in the library's handling of URLs with the `data:` scheme. When Axios on Node.j...
The Lab · 2026-04-16 21:22:54 · GitHub Issues
A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory update for any service relying on SPDY/3 communication. The flaw, tracked as CVE-2026-35469, resides in the library's frame parser, which fails to validate attacker-controlled counts and lengths...
The Lab · 2026-04-18 02:22:38 · GitHub Issues
A critical security vulnerability in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled data before allocating system memory. This allows a remote peer to sen...
The Lab · 2026-04-19 10:22:38 · GitHub Issues
A critical security flaw in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The vulnerability, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before allocating memory. This allows a remote peer...
The Lab · 2026-04-19 11:22:34 · GitHub Issues
A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory security update for countless dependent projects. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before a...