WhisperX tag archive

#security-patch

This page collects WhisperX intelligence signals tagged #security-patch. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Lab · 2026-03-26 01:27:32 · GitHub Issues

1. gRPC-Go v1.79.3 Patches Critical Authorization Bypass in HTTP/2 Path Validation

A critical security flaw in the core routing logic of Google's gRPC-Go library has been patched, exposing servers to potential authorization bypass. The vulnerability, tracked as CVE-2026-33186, stems from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was found to be overly permissiv...

The Lab · 2026-03-29 03:27:03 · GitHub Issues

2. Python cryptography Library Patches Critical Private Key Leak in Rare Binary Curves (CVE-2026-26007)

A critical vulnerability in the widely-used Python cryptography library has been patched, exposing a potential path for attackers to steal portions of a user's private key. The flaw, tracked as CVE-2026-26007, was discovered in the library's handling of specific, uncommon elliptic curves. An attacker could exploit this...

The Lab · 2026-03-31 01:27:05 · GitHub Issues

3. Go-Git v5.17.1 Patches Critical Index Decoder Vulnerability (CVE-2026-33762)

A critical security flaw in the widely used `go-git` library has been patched in version 5.17.1. The vulnerability, tracked as CVE-2026-33762, resides in the index decoder for format version 4. The decoder fails to perform a crucial validation step, allowing a maliciously crafted Git index file to trigger an out-of-bou...

The Lab · 2026-04-01 06:27:01 · GitHub Issues

4. Cryptography Library Patches Critical DNS Validation Flaw (CVE-2026-34073)

A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a fundamental flaw in how the software validates DNS name constraints. The issue, tracked as CVE-2026-34073, resided in versions prior to 46.0.5. The core failure was that DNS name constraints were only validated...

The Lab · 2026-04-02 00:26:57 · GitHub Issues

5. Vite v5 Security Update Addresses Critical File-Serving Bypass Vulnerability (CVE-2025-58751)

A critical security vulnerability in the Vite development server, tracked as CVE-2025-58751, allows files to bypass configured security restrictions. The flaw enables files starting with the same name as those in a project's public directory to be served, effectively ignoring the `server.fs` settings designed to limit ...

The Lab · 2026-04-03 07:27:06 · GitHub Issues

6. Go-Git v5.17.1 Patches Critical Index Decoder Vulnerability (CVE-2026-33762)

A critical security flaw in the widely used `go-git/v5` library has been patched, exposing countless Go-based applications and CI/CD pipelines to potential denial-of-service attacks. The vulnerability, tracked as CVE-2026-33762, resides in the library's index decoder for format version 4. The flaw allows a maliciously ...

The Lab · 2026-04-04 14:27:06 · GitHub Issues

7. Security Alert: go-jose/v4 Library Update Patches Critical Panic Vulnerability in JWE Decryption (CVE-2026-34986)

A critical security vulnerability in the widely-used `go-jose/go-jose/v4` library has been patched, forcing a mandatory update for any project handling JSON Web Encryption (JWE). The flaw, tracked as CVE-2026-34986, causes a panic—a complete runtime crash—when decrypting a JWE object if its `alg` field specifies a key ...

The Lab · 2026-04-06 12:27:15 · GitHub Issues

8. Vite Dev Server Security Flaw Exposes Denied Files on Windows via Backslash URL

A critical security vulnerability in the Vite development server allows attackers to bypass file access restrictions on Windows systems. The flaw, tracked as CVE-2025-62522, enables the retrieval of files explicitly denied by the `server.fs.deny` configuration if a malicious URL ends with a backslash (`\`). This bypass...

The Lab · 2026-04-06 20:27:24 · GitHub Issues

9. Vite Dev Server Security Flaw Exposes Source Maps to Network Attackers

A critical security vulnerability in the Vite development server allows attackers to access any file ending in `.map` on the host machine, potentially exposing sensitive source code and internal project structure. The flaw, tracked as GHSA-4w7w-66w2-5vf9, is present in versions prior to Vite 8.0.5. This is not a theore...

The Lab · 2026-04-08 21:27:19 · GitHub Issues

10. Vite v7.3.2 Patches Critical File Exposure Vulnerability (CVE-2026-39364)

A critical security vulnerability in the Vite development server has been patched, exposing sensitive files to remote browsers. The flaw, tracked as CVE-2026-39364, allows the contents of files explicitly blocked by the `server.fs.deny` configuration to be returned to a client. This bypass of intended access controls c...

The Lab · 2026-04-10 06:39:45 · GitHub Issues

11. Vite Dev Server Security Flaw Exposes Denied Files on Windows via Backslash URL

A critical security vulnerability in the Vite development server allows attackers to bypass file access restrictions on Windows systems. The flaw, tracked as CVE-2025-62522, enables the retrieval of files explicitly denied by the `server.fs.deny` configuration if a malicious URL ends with a backslash (`\`). This bypass...

The Lab · 2026-04-10 06:39:46 · GitHub Issues

12. Vite Dev Server Security Flaw Exposes Denied Files on Windows via Backslash URL

A critical security vulnerability in the Vite development server allows attackers to bypass file access restrictions on Windows systems. The flaw, tracked as CVE-2025-62522, enables the retrieval of files explicitly denied by the `server.fs.deny` configuration if a malicious URL ends with a backslash (`\`). This bypass...

The Lab · 2026-04-14 08:22:46 · GitHub Issues

13. Cryptography Library Patches Critical Private Key Leak in Rare Binary Curves (CVE-2026-26007)

The widely-used Python cryptography library has patched a critical vulnerability that could allow an attacker to steal portions of a user's private key. The flaw, tracked as CVE-2026-26007, resides in the library's handling of specific, uncommon elliptic curves known as binary curves. An attacker could exploit this by ...

The Lab · 2026-04-14 10:22:46 · GitHub Issues

14. Vite Dev Server Security Flaw Exposes Source Maps to Network Attackers

A critical security vulnerability in the Vite development server allows attackers to access source map files from outside a project's directory. The flaw, tracked as CVE-2026-39365, is triggered when any file ending in `.map` is requested, potentially exposing sensitive debugging information and source code structure t...

The Lab · 2026-04-15 09:22:39 · GitHub Issues

15. qs Library Security Patch: CVE-2025-15284 Exposes Array Parsing Inconsistency

A critical security update has been issued for the widely used `qs` library, patching a vulnerability (CVE-2025-15284) that created an inconsistency in how the library enforces array size limits. The flaw resided in the `arrayLimit` option, which failed to apply its restrictions to bracket notation array parsing (`a[]=...

The Lab · 2026-04-17 20:22:51 · GitHub Issues

16. Moby spdystream v0.5.1 Patches Critical Memory Exhaustion Vulnerability (CVE-2026-35469)

A critical security flaw in the widely used `moby/spdystream` library exposes services to remote memory exhaustion attacks. The vulnerability, tracked as CVE-2026-35469, resides in the SPDY/3 frame parser, which fails to validate attacker-controlled input before allocating memory. This allows a remote peer to send a sm...

The Lab · 2026-04-22 00:22:40 · GitHub Issues

17. Python-dotenv v1.2.2 Patches Critical Symlink Vulnerability (CVE-2026-28684) Allowing Arbitrary File Overwrite

A critical security flaw in the widely-used python-dotenv library has been patched, exposing projects to arbitrary file overwrite attacks. The vulnerability, tracked as CVE-2026-28684 (GHSA-mf9w-mj56-hr94), resides in the `set_key()` and `unset_key()` functions. These functions, responsible for modifying `.env` files c...

The Lab · 2026-04-22 15:27:40 · GitHub Issues

18. CVE-2026-41140: Poetry 2.3.4 Patches Critical Path Traversal Vulnerability in Tar Extraction

Poetry, the widely adopted Python dependency management tool, has released version 2.3.4 to address a critical path traversal vulnerability in its tar extraction functionality. Tracked as CVE-2026-41140, the security flaw allows an attacker to write files to arbitrary locations on a system during package installation, ...

The Lab · 2026-04-23 06:54:07 · GitHub Issues

19. PostgreSQL Driver pgx Patches SQL Injection When Simple Protocol Meets Dollar Quoting

A critical SQL injection vulnerability has been identified and patched in github.com/jackc/pgx/v5, a widely adopted PostgreSQL driver for Go applications. The flaw, tracked as GHSA-j88v-2chj-qfwx, was resolved in version 5.9.2, with users advised to upgrade from the affected v5.9.0 release. The vulnerability carries si...

The Lab · 2026-04-23 12:54:14 · GitHub Issues

20. Prometheus Web UI XSS Vulnerability CVE-2026-40179 Patched in Security Update to v0.311.2

A critical stored cross-site scripting (XSS) vulnerability in the Prometheus monitoring system's web interface has been addressed through an emergency dependency update. The flaw, tracked as CVE-2026-40179, allows attackers to inject malicious HTML or JavaScript code via specially crafted metric names, which then execu...