The Lab · 2026-03-26 08:27:09 · GitHub Issues
A critical security flaw with a maximum severity score of 9.8 has been identified in the widely used Django Channels package, version 3.0.5. The vulnerability, tracked as WS-2022-0365, resides within the transitive dependency `cryptography-37.0.4`. This flaw represents the highest-risk exposure in a suite of 23 distinc...
The Lab · 2026-03-27 06:26:59 · GitHub Issues
A critical security vulnerability in the widely-used Tokio asynchronous runtime for Rust has been patched, forcing a mandatory update for any project using the broadcast channel feature. The flaw, tracked as GHSA-rr8g-9fpq-6wmg, resides in the broadcast channel's internal cloning mechanism. The channel only required th...
The Lab · 2026-03-27 07:27:01 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-03-27 09:27:08 · GitHub Issues
A high-severity security flaw has been disclosed in the `minimatch` library, a core component used by millions of JavaScript projects for file pattern matching. The vulnerability, classified as a Regular Expression Denial of Service (ReDoS), carries a CVSS score of 7.5 and could allow attackers to crash or severely deg...
The Lab · 2026-03-27 11:27:33 · GitHub Issues
A critical security update has been released for the widely-used `node-forge` cryptography library, patching a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function. When this function is called with a zero value as input, it triggers...
The Lab · 2026-03-27 12:27:33 · GitHub Issues
A critical security vulnerability in the widely-used `node-forge` cryptography library has been disclosed, prompting an urgent update to version 1.4.0. The flaw, rated HIGH severity, is a Denial of Service (DoS) vulnerability within the `BigInteger.modInverse()` function. When called with a zero value, the function ent...
The Lab · 2026-03-27 16:27:37 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-03-28 05:27:01 · GitHub Issues
Rust 安全团队发布关键安全公告 RUSTSEC-2024-0437,指出 `protobuf` 库的 2.28.0 版本存在一个可导致崩溃的漏洞。该漏洞源于解析特定 Protobuf 消息时发生的无限递归,可能引发拒绝服务(DoS)。虽然其严重性被标记为“中等”且并非远程代码执行(RCE),但它直接阻塞了依赖审计和持续集成(CI)流程,迫使相关项目必须采取行动。
受影响的依赖链清晰显示了问题的传导路径:有问题的 `protobuf 2.28.0` 版本被 `prometheus 0.13.4` 所依赖,而后者又被 `dewey 0.1.0` 项目使用。官方建议的修复方案是升级到 `protobuf >= 3.7.2` 版本。然...
The Lab · 2026-03-28 06:27:05 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-03-29 01:26:56 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-03-29 01:27:00 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-03-29 02:27:05 · GitHub Issues
A critical Denial of Service vulnerability in the widely-used `node-forge` cryptography library has been patched in version 1.4.0. The flaw, rated HIGH severity, resides in the `BigInteger.modInverse()` function inherited from the bundled jsbn library. When this function is called with a zero value as input, the intern...
The Lab · 2026-03-29 03:27:06 · GitHub Issues
A high-severity Denial of Service vulnerability has been disclosed in the widely-used `node-forge` cryptography library, forcing development teams to urgently update dependencies. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function inherited from the bundled jsbn library. When this fu...
The Lab · 2026-03-29 04:27:06 · GitHub Issues
A high-severity Denial of Service (DoS) vulnerability has been patched in the widely used `node-forge` cryptography library, forcing projects to urgently update to version 1.4.0. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function inherited from the bundled jsbn library. When this fun...
The Lab · 2026-03-29 04:27:08 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-03-29 12:27:03 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-04-01 20:27:22 · GitHub Issues
A critical security update for the widely-used `golang.org/x/crypto` library patches two severe vulnerabilities in SSH servers that could allow attackers to trigger unbounded memory consumption and denial-of-service attacks. The update, jumping from version 0.37.0 to 0.45.0, addresses flaws that directly impact the sta...
The Lab · 2026-04-07 16:27:24 · GitHub Issues
A critical security update for the widely-used `node-forge` cryptography library patches a high-severity Denial of Service (DoS) vulnerability. The flaw, tracked as CVE-2026-33891, resides in the `BigInteger.modInverse()` function, which is inherited from the bundled `jsbn` library. When this function is called with a ...
The Lab · 2026-04-08 02:27:10 · GitHub Issues
A critical security vulnerability has been identified in the widely used `addressable` Ruby gem, exposing countless applications to potential denial-of-service attacks. The flaw, tracked as CVE-2024-35252, resides in the library's URI template implementation. Attackers can exploit a weakness in the regular expression p...
The Lab · 2026-04-11 06:22:39 · GitHub Issues
A critical security flaw in a widely used WebSocket library has been patched, addressing a Regular Expression Denial of Service (ReDoS) vulnerability that could have allowed attackers to crash or degrade server performance. The vulnerability, tracked as CVE-2020-7662, was present in the `websocket-extensions` library, ...