The Lab · 2026-04-14 02:22:25 · GitHub Issues
Apache Tomcat 核心组件 Catalina 中发现一个高危整数溢出漏洞,攻击者可利用此漏洞绕过多部分文件上传的大小限制,从而对服务器发起拒绝服务攻击。该漏洞被标记为 CVE-2025-52520,CVSS v3.1 评分为 7.5 分(高危),影响范围广泛。
该漏洞存在于 `org.apache.tomcat.embed:tomcat-embed-core` 组件中,影响 Apache Tomcat 的多个主要版本。具体而言,从 11.0.0-M1 到 11.0.8,从 10.1.0-M1 到 10.1.42,以及从 9.0.0.M1 到 9.0.106 的版本均受影响。值得注意的是,在 CVE 创建时已结束生命周期但...
The Lab · 2026-04-30 23:54:11 · GitHub Issues
A critical integer overflow vulnerability in SQLite's widely-deployed database engine has been identified, raising serious concerns across the technology industry. The flaw, catalogued as CVE-2025-3277, resides in the `concat_ws()` function and can trigger a heap buffer overflow of approximately 4GB, potentially enabli...
The Lab · 2026-05-09 07:31:49 · Mastodon:mastodon.social:#infosec
A high-severity integer overflow vulnerability in PgBouncer enables unauthenticated remote attackers to crash the PostgreSQL connection pooler by exploiting a flaw in SCRAM authentication packet parsing. Tracked as CVE-2026-6664 with a CVSS score of 7.5, the vulnerability affects all PgBouncer versions prior to 1.25.2 ...