WhisperX tag archive

#dependency vulnerability

This page collects WhisperX intelligence signals tagged #dependency vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (12)

The Lab · 2026-03-26 21:27:16 · GitHub Issues

1. Netty HTTP/2 Zero-Byte Frame Bypass Exposes Servers to DoS Flood (CVE-2026-33871)

A critical vulnerability in the widely-used Netty networking framework exposes HTTP/2 servers to a potent denial-of-service (DoS) attack. Tracked as CVE-2026-33871, the flaw allows a remote attacker to trigger a service outage by flooding a server with specially crafted CONTINUATION frames. The attack exploits a bypass...

The Lab · 2026-03-31 06:27:12 · GitHub Issues

2. CVE-2017-1000188: Legacy EJS Library ejs-0.8.8.tgz Harbors Medium-Severity XSS Vulnerability

A legacy version of the popular Embedded JavaScript templating library, EJS, remains an active security liability in modern software projects. The specific version ejs-0.8.8.tgz, detected as a dependency, contains a documented Cross-Site Scripting (XSS) vulnerability (CVE-2017-1000188) that could lead to remote code in...

The Lab · 2026-03-31 06:27:21 · GitHub Issues

3. CVE-2024-47764: Medium-Severity Cookie Parsing Flaw Exposes Node.js Servers to Manipulation

A newly disclosed vulnerability in a foundational Node.js library opens a subtle but exploitable path for attackers to manipulate cookie data on web servers. CVE-2024-47764, rated with medium severity, targets the widely used `cookie` library, a core component for parsing and serializing HTTP cookies. The flaw allows a...

The Lab · 2026-04-07 01:26:55 · GitHub Issues

4. Python Requests Library Security Flaw: CVE-2026-25645 Exposes Temp Directory Hijack Risk

A critical security vulnerability has been disclosed in the ubiquitous Python `requests` library, exposing a path traversal and file hijack risk within its internal file extraction utility. The flaw, tracked as CVE-2026-25645, resides in the `requests.utils.extract_zipped_paths()` function. This utility uses a predicta...

The Lab · 2026-04-14 01:22:41 · GitHub Issues

5. CVE-2025-59436: Low-Severity Vulnerability Detected in FDM Monster Dependency Chain

A low-severity vulnerability, CVE-2025-59436, has been identified within the dependency chain of the FDM Monster project. The flaw resides in the `ip-1.1.9.tgz` library, a transitive dependency pulled in via the `ftp-srv` package. This finding highlights the persistent risk of inherited security weaknesses in complex s...

The Lab · 2026-04-19 10:22:38 · GitHub Issues

6. Moby spdystream v0.5.1 Patches Critical Memory Exhaustion Vulnerability (CVE-2026-35469)

A critical security flaw in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The vulnerability, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before allocating memory. This allows a remote peer...

The Lab · 2026-04-19 11:22:34 · GitHub Issues

7. Moby spdystream v0.5.1 Patches Critical Memory Exhaustion Vulnerability (CVE-2026-35469)

A critical memory exhaustion vulnerability in the widely used `moby/spdystream` library has been patched, forcing a mandatory security update for countless dependent projects. The flaw, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled counts and lengths before a...

The Lab · 2026-04-20 13:23:00 · GitHub Issues

8. Red Hat UHC Portal Urgently Updates Axios to Patch Critical RCE Vulnerability CVE-2026-40175

A critical security vulnerability in the widely used Axios HTTP client library has triggered an urgent update within Red Hat's UHC Portal. The flaw, tracked as CVE-2026-40175, exposes systems to potential Remote Code Execution (RCE) and cloud compromise, prompting immediate remediation efforts. This is not a theoretica...

The Lab · 2026-04-26 14:54:07 · GitHub Issues

9. Gateway Framework Auto-Installs Unsigned Python Packages, Raising Critical Supply Chain Risk

A critical supply chain vulnerability has been identified in a gateway framework that automatically installs missing Python packages without verification. The flaw, documented in a security disclosure, stems from code that attempts to install dependencies like flask, requests, and flask-cors via subprocess on import if...

The Lab · 2026-04-28 04:54:11 · GitHub Issues

10. CVE-2026-41650: fast-xml-parser XMLBuilder Flaw Allows Comment and CDATA Injection via Unescaped Delimiters

A security vulnerability has been identified in fast-xml-parser, a widely used open-source XML parsing library maintained by NaturalIntelligence. The flaw, tracked as CVE-2026-41650 (GHSA-gh4j-gqv2-49f6), resides in the XMLBuilder component and stems from improper handling of unescaped delimiters during XML processing....

The Lab · 2026-04-29 02:54:10 · GitHub Issues

11. CVE-2026-40973: High-Severity Vulnerability Detected in Spring Boot 3.5.3 Dependency in MidnightBSD Advisory Repository

A high-severity vulnerability, cataloged as CVE-2026-40973, has been identified within the Spring Boot 3.5.3 library component embedded in the MidnightBSD/security-advisory repository. The flaw was detected through automated dependency scanning and surfaced during analysis of the project's HEAD commit on the master bra...

The Lab · 2026-05-13 17:48:21 · GitHub Issues

12. SAP UI5 Toolchain Exposed to Three High-Severity Axios Vulnerabilities via Dependency Chain

Three high-severity security vulnerabilities embedded in the Axios HTTP client library have been traced through the dependency chain of the SAP UI5 development toolchain, specifically affecting `@sap-ux/project-access`. The most critical flaw—CVE-2025-62718—bypasses NO_PROXY protections via RFC 1122 loopback subnet man...