WhisperX tag archive

#parsing-vulnerability

This page collects WhisperX intelligence signals tagged #parsing-vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-15 09:22:39 · GitHub Issues

1. qs Library Security Patch: CVE-2025-15284 Exposes Array Parsing Inconsistency

A critical security update has been issued for the widely used `qs` library, patching a vulnerability (CVE-2025-15284) that created an inconsistency in how the library enforces array size limits. The flaw resided in the `arrayLimit` option, which failed to apply its restrictions to bracket notation array parsing (`a[]=...

The Lab · 2026-05-02 21:54:08 · GitHub Issues

2. python-multipart Parsing Flaw Enables Denial-of-Service via Oversized Multipart Bodies

A denial of service vulnerability has been identified in python-multipart, a widely used Python library for parsing multipart/form-data requests. The flaw, tracked as CVE-2026-40347, affects versions up to and including 0.0.20, with a patched release available in version 0.0.26. The vulnerability stems from inefficient...