ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -script operation is missing policy checks and that could result in both reading from paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
Due to a missing check in the APNG encoder and external delegates it is possibly to bypass the policy and write to a disallowed path.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
A memory leak will occur when a blob cannot be opened in the YUV decoder.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
When an allocation fails in the VIFF encoder a memory leak will occus.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
An invalid tiff:tile-geometry will cause a memory leak in the TIFF encoder.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When an allocation fails in the TIFF encoder a small memory leak will occur.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
When a temporary file can not be created a small memory leak will happen in the TIFF encoder.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
A memory leak will occur in the MIFF encoder when an allocation fails.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
When a blob can not be opened a memory leak will occur when encoding a JNG file.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
A memory leak will occur in the ICON decoder when an allocation fails.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When a specific operation fails in the hough lines operation a small memory leak will occur.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When transforming an image to the log colorspace a small memory leak happens when the operation fails.
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When a profile is displayed with the identify command and the value is not printable a single byte at the end of the profile can be printed.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
When providing invalid arguments to the connected-components option an infinite loop will occur.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Because of a missing null check when parsing an XMP profile a use after free will happen that might result in a crash.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
Running an X11 import with a crafted window title can result in a heap buffer over-write.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
hubuum_client diagnostics can expose sensitive request, response, import/export, task, delivery, or server-provided data when applications format or log errors and public models.
When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwest client directly. The bypass includes password login, bearer-token validation, authentication-provider discovery, health and readiness probes, export-output downloads, and unified-search streams.
The built-in async and blocking clients used reqwest's default redirect policy. BaseUrl constrains the initial request to the configured origin and path prefix, but redirect processing occurs after that validation. reqwest retains sensitive headers when a redirect changes only the path on the same scheme, host, and port. A redirect from a Hubuum endpoint to another path on a shared origin could therefore carry the bearer Authorization header outside the …
The httplib2 HTTP client library performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate. A malicious or compromised HTTP server can return a small compressed payload (approximately 150 KB) that expands to an arbitrarily large size in memory (150 MB or more), causing MemoryError or OOM-kill in the client process. This is a classic decompression bomb (zip bomb) attack against the HTTP client. Any application using …
GitPython's check_unsafe_options guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for every guarded method (clone/clone_from, fetch/pull/push, ls_remote, iter_commits, blame, archive) by smuggling an option token inside the VALUE of a single-character kwarg. In the default allow_unsafe_options=False configuration this yields arbitrary command execution via –upload-pack.
GitPython's unsafe_git_clone_options denylist omits –template. git clone –template=<dir> copies <dir>/hooks/ into the new repository and runs them (post-checkout fires during clone), so a caller who can influence clone options can achieve arbitrary command execution in the default allow_unsafe_options=False configuration.
In GitPython <= 3.1.52, the config writer neutralizes only CR, LF, and NUL in configuration names, but writes section names into the […] header with no other escaping. A section/subsection name that contains ] [ " closes the intended header and opens a second same-line section, injecting an arbitrary config directive — with no newline required. Because a submodule name is attacker-controlled data (it comes from a repository's .gitmodules, or …
The fix for GHSA-rwj8-pgh3-r573 stopped Repo.clone_from() from running caller-supplied URLs through os.path.expandvars(), but it guarded only that one caller. Remote.create() — reached from the public Repo.create_remote() and its Remote.add() alias — still passes an attacker-influenceable URL through Git.polish_url() with the default expand_vars=True. A URL such as http://attacker.example/${AWS_SECRET_ACCESS_KEY}/repo.git is expanded server-side to embed the hosting process's environment secret, written into .git/config, and then transmitted to the attacker's host on the next …
Diffable.diff() forwards **kwargs straight into diff/diff_tree with no check_unsafe_options guard. Diffable is mixed into Commit, Tree, IndexFile, and Submodule, giving a broad surface. git diff –output=<path> writes real patch content to an attacker-chosen path, enabling arbitrary file overwrite.
An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire frps process with a single five-byte message. When the gateway parses an SSH exec channel request in pkg/ssh/server.go, it adds a small constant to a four-byte length value taken directly from the request. Because that length is fully attacker-controlled, a value of 0xFFFFFFFF makes the addition wrap around to a tiny …
The OpenAPI adapter's spec-change poller (OpenApiSpecPoller) re-fetched the configured spec url on a timer using a raw global fetch(), bypassing the SSRF guard (safeFetch / assertUrlSafe) that OpenAPIToolGenerator.fromURL() applies to the initial spec load. As a result, the pinning/DNS-resolution hardening delivered via mcp-from-openapi >= 2.5.0 (advisory GHSA-65h7-9wrw-629c) protected the initial load but not the recurring poll of the same URL. When polling is enabled against an untrusted or attacker-influenceable spec …
What kind of vulnerability is it? Who is impacted? A user granted READ permission on a single, exact key can use the Watch gRPC API with clientv3.WithFromKey() (an open-ended, "from this key to the end of the keyspace" watch) to receive watch events for every key lexicographically greater than or equal to their permitted key — not just the one key they were granted. This is an authorization bypass in …
What kind of vulnerability is it? Who is impacted? A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and each is tracked in the pending map. Unbounded goroutine and map growth exhausts memory in the etcd process, causing loss of availability for the etcd …
AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary code by placing a malicious shared library in the directory from which the AppImage is launched.
In electron-builder's builder-util-runtime package, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization". Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab's personal access token flow) and mixed-case Authorization (used by GitLab's Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination.
Cloudreve's WOPI PUT_RELATIVE handler treats X-WOPI-SuggestedTarget as a path, not a filename. It splits the header on / and joins the segments onto the source file's directory with URI.JoinRaw, which feeds Go's url.JoinPath. url.JoinPath resolves ./.. segments, so a slash-bearing target such as a/../../evil.docx collapses to a location outside the source file's directory. The lower-level upload path then validates only the final, already-cleaned basename (evil.docx), which is harmless, and checks …
Cloudreve's WOPI PUT_RELATIVE handler treats X-WOPI-SuggestedTarget as a path, not a filename. It splits the header on / and joins the segments onto the source file's directory with URI.JoinRaw, which feeds Go's url.JoinPath. url.JoinPath resolves ./.. segments, so a slash-bearing target such as a/../../evil.docx collapses to a location outside the source file's directory. The lower-level upload path then validates only the final, already-cleaned basename (evil.docx), which is harmless, and checks …
GET /api/v4/user/search is available to any logged-in user. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. A normal logged-in user can therefore enumerate and retrieve the email (plus nickname, avatar, creation …
GET /api/v4/user/search is available to any logged-in user. The service calls userClient.SearchActive, but despite its name that method filters only by email/nickname keyword and never adds a StatusActive predicate — while the sibling lookups GetActiveByID and GetActiveByDavAccount, defined a few lines above it, do. Search hits are serialized at RedactLevelUser, which includes the email address. A normal logged-in user can therefore enumerate and retrieve the email (plus nickname, avatar, creation …
Cloudreve's built-in image processor decodes user-supplied images with Go's standard-library decoders (image/png, image/jpeg, image/gif) and guards only the compressed file size — never the decoded pixel dimensions. Go's decoders allocate a pixel buffer sized bytesPerPixel × width × height taken straight from the image header (e.g. a PNG's IHDR), with no upper bound on width/height. A tiny (tens-of-bytes) image that declares enormous dimensions therefore forces a multi-gigabyte-to-terabyte allocation (make([]uint8, …)), …
Cloudreve's built-in image processor decodes user-supplied images with Go's standard-library decoders (image/png, image/jpeg, image/gif) and guards only the compressed file size — never the decoded pixel dimensions. Go's decoders allocate a pixel buffer sized bytesPerPixel × width × height taken straight from the image header (e.g. a PNG's IHDR), with no upper bound on width/height. A tiny (tens-of-bytes) image that declares enormous dimensions therefore forces a multi-gigabyte-to-terabyte allocation (make([]uint8, …)), …
When an authenticated recipient of a single-file share opens the file event stream (GET /api/v4/file/events?uri=<share-root>), Cloudreve validates the URI by listing it and then subscribes the caller to parent.ID(). For a single-file share, the share navigator resolves the bare share-root URI to the owner-side parent folder of the shared file (not the file), while the visible listing is filtered down to just the shared file. The event hub then keys …
When an authenticated recipient of a single-file share opens the file event stream (GET /api/v4/file/events?uri=<share-root>), Cloudreve validates the URI by listing it and then subscribes the caller to parent.ID(). For a single-file share, the share navigator resolves the bare share-root URI to the owner-side parent folder of the shared file (not the file), while the visible listing is filtered down to just the shared file. The event hub then keys …
Cloudreve WOPI access tokens are generated as <session-id>.<random-secret>, but the WOPI middleware validates only the session id prefix and never compares the supplied token to the stored token. In addition, a WOPI viewer session does not store or enforce the requested viewer action. A session created for a view or preview action can still call WOPI write routes if the underlying file is writable by the session user.
Cloudreve WOPI access tokens are generated as <session-id>.<random-secret>, but the WOPI middleware validates only the session id prefix and never compares the supplied token to the stored token. In addition, a WOPI viewer session does not store or enforce the requested viewer action. A session created for a view or preview action can still call WOPI write routes if the underlying file is writable by the session user.
Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to Admin.Read but not Admin.Write can call POST /api/v4/admin/policy/oauth/signin and update OneDrive storage policy credentials. The route is inside the admin group that requires Admin.Read, but it does not add the local Admin.Write guard used by sibling policy mutation routes. Its handler persists attacker-supplied secret and app_id values into the selected …
Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to Admin.Read but not Admin.Write can call POST /api/v4/admin/policy/oauth/signin and update OneDrive storage policy credentials. The route is inside the admin group that requires Admin.Read, but it does not add the local Admin.Write guard used by sibling policy mutation routes. Its handler persists attacker-supplied secret and app_id values into the selected …
Cloudreve exposes two admin node test endpoints under the Admin.Read OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for Admin.Read to trigger operational network actions that should require Admin.Write.
Cloudreve exposes two admin node test endpoints under the Admin.Read OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for Admin.Read to trigger operational network actions that should require Admin.Write.
Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files in the user's home directory (such as .zshenv), leading to code execution outside of seatbelt sandbox restrictions. Reliably exploiting this required the user to clone a malicious repository containing prompt injection …
The function ext.NativeTypes(ParseStructTag("json")) does not honour the encoding/json skip directive json:"-". Fields tagged json:"-" are registered in the CEL type system under the literal name "-" and are readable from any user-submitted CEL expression via dyn(obj)["-"]. Additionally, newNativeTypes silently registers every nested struct reachable from the type passed to NativeTypes, including types from third-party dependencies the developer never examined.
Budibase's central outbound-fetch guard (fetchWithBlacklist) prevents SSRF/DNS-rebinding by resolving the target hostname, checking every resolved IP against the blacklist, and pinning the connection to the validated IP. The pin is implemented as a Node http(s).Agent (makePinnedAgent). The fix for CVE-2026-54353 relies on this pin to stop DNS rebinding. The REST datasource integration (@budibase/server) calls fetchWithBlacklist but performs the actual request with undici's fetch. undici does not support the Node agent …
The uploadUrl() function in packages/server/src/utilities/fileUtils.ts uses a bare fetch(url) call without any SSRF protection. This function is invoked when the AI table generation feature processes LLM-generated attachment column values that are strings (URLs). A builder-level user can craft prompts that cause the LLM to generate internal IP addresses or cloud metadata endpoints as attachment URLs. When generateRows() calls processAttachments(), these URLs are fetched server-side without blacklist validation, allowing the attacker …
This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p (PostgreSQL SQL injection), reported in the same original disclosure and split per GitHub CNA guidance (rule 4.2.11) since it affects a separate integration, has a distinct attack precondition, and requires a separate patch. The MySQL integration enables multipleStatements: true on the connection, permitting semicolon-separated multi-statement execution. During table introspection, table names retrieved from INFORMATION_SCHEMA.TABLES are interpolated into a DESCRIBE query …
expand() bounds the number of results it produces (the max option, 100_000 by default) but not their length. By chaining many brace groups, an attacker keeps the result count under max while making every result grow with the number of groups. Building max long results — plus the intermediate arrays combined at each brace group — exhausts memory and crashes the Node process with an uncatchable out-of-memory error. try/catch around …
http4s-blaze-server aggregates the fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service via OutOfMemoryError.
http4s-blaze-server aggregates the fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service via OutOfMemoryError.
http4s-blaze-server aggregates the fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denial of service via OutOfMemoryError.
Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (http/src/main/java/org/http4s/blaze/http/parser/) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default BlazeServerBuilder with no non-default configuration.
Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (http/src/main/java/org/http4s/blaze/http/parser/) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default BlazeServerBuilder with no non-default configuration.
Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (http/src/main/java/org/http4s/blaze/http/parser/) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default BlazeServerBuilder with no non-default configuration.
blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. X-Forwarded-For, internal-auth headers) that a fronting proxy sanitized from the request-header section, bypassing header-based trust decisions in the application.
blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. X-Forwarded-For, internal-auth headers) that a fronting proxy sanitized from the request-header section, bypassing header-based trust decisions in the application.
blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. X-Forwarded-For, internal-auth headers) that a fronting proxy sanitized from the request-header section, bypassing header-based trust decisions in the application.
An attacker can keep password access to a victim's account after the victim starts using it. The attack runs in three steps. First, with open registration, the attacker signs up using the victim's email and a password the attacker picks. The account stays unverified, so the attacker cannot use it yet. Later the real owner signs in with a magic link or an email OTP. That step marks the account …
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. Certain CLI subcommands wrote credential and configuration files with world-readable permissions on Unix-like systems with a default umask, allowing other local users on the same host to read credentials.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting encrypted: true on the S3LoggingOptions property of an AWS CodeBuild project construct produces the opposite of the intended behavior, disabling encryption on CodeBuild build logs stored in S3.
The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. An issue exists where, under certain circumstances, improper neutralization of argument delimiters in the install_packages() method allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.
The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. An issue exists where, if the data used to enforce this policy …
@fastify/static is vulnerable to a bypass of route-based middleware and guards via non-leading .. and %2E%2E path segments. find-my-way does not normalize .. when matching routes, so a request such as /foo/../deep/secret.txt matches the static plugin's catch-all instead of the guarded /deep/*. The getPathnameForSend helper introduced by the fix for GHSA-x428-ghpx-8j92 only guards against the %2F variant; .. and %2E%2E survive the decodeURI + encodeURI round-trip and are then collapsed …
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as //file, /./file, or /public/../private/file bypass allowedPath filtering while resolving to the intended file on disk. Applications that use allowedPath as a security boundary to restrict access to specific static files or path subtrees may unintentionally expose files that were intended to be denied.
An org subscription action can run against the wrong org. The actions are cancel, change plan, restore, and open the billing portal. The plugin checks permission against the org id in the request query string. It then runs the action against the caller's active org from their session. When these two ids differ, a member can act on billing for an org they may not manage. The target is always …
@better-auth/scim used the same logical provider ID for SCIM provider configuration and account ownership. SCIM token issuance did not reject all account-provider namespaces. An authenticated user could therefore mint a SCIM token whose provider ID matched an existing SSO, SAML, OIDC, generic OAuth, or social provider. SCIM user routes then selected account rows by that provider ID and treated those users as SCIM-managed, even when the SCIM token had never …
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in @backstage/plugin-auth-backend matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such as https://*.example.com/callback, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such as https://attacker.example/x.example.com/callback. This applies to auth.experimentalDynamicClientRegistration.allowedRedirectUriPatterns as well as the allowedClientIdPatterns and allowedRedirectUriPatterns …
@anephenix/hub starts a setInterval polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies — which requires no authentication or special configuration — the interval and the pending request object are never cleaned up, even after the socket is closed. An unauthenticated attacker who opens many WebSocket connections and ignores all server RPC messages will therefore cause the server to …
The Budibase Worker service exposes a public, unauthenticated API endpoint (GET /api/global/users/tenant/:id) that returns sensitive user information including tenantId, userId, email, and ssoId. The endpoint is registered in the PUBLIC_ENDPOINTS list with a TODO comment acknowledging it "should be an internal API." Any unauthenticated party can enumerate user emails or IDs to extract sensitive tenant and user metadata, enabling targeted attacks against multi-tenant deployments.
Budibase attaches a REST datasource's stored credentials (Bearer/Basic tokens and static headers) to an outgoing request before it decides which host the request goes to, and never checks that the destination host matches the datasource. A query's request path can be pointed at any host (via an absolute URL or a user-supplied {{ parameter }}), so the stored credentials are delivered to an attacker-chosen server. Because a query can be …
The /api/users/metadata and /api/users/metadata/:id endpoints in @budibase/server return full global user profiles to any user with POWER role or above. For SSO-authenticated users (OIDC, Google), the response includes oauth2.accessToken and oauth2.refreshToken fields, leaking identity provider credentials to other users who should not have access to them.
A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands.
When creating a MongoDB datasource, Budibase passes the tlsCertificateKeyFile and tlsCAFile fields straight to the MongoDB driver as server-side file paths. On Budibase Cloud a customer cannot place files on the server, so these fields only let a builder reference arbitrary absolute paths on the underlying multi-tenant server. When the datasource is verified, the driver performs a real filesystem read of that path, and the error differs by file state, …
In Budibase v3.39.4, a regression in the authorization level for the S3 attachment upload endpoint allows any BASIC app user to obtain S3 PutObject presigned URLs. The endpoint uses TABLE/WRITE permission level instead of the intended BUILDER level defined in v3.39.3. Additionally, the controller does not pin the target bucket to the datasource's configured bucket, allowing writes to any S3 bucket the stored IAM credentials can access.
Budibase 3.39.19 (commit 03fbabae4) is affected by a privilege-escalation / missing-authorization flaw in the public role-assignment API. An app-scoped builder (a user who builds only specific apps — user.builder.apps = [appA], not a global builder or admin) can grant themselves builder access to ANY other app in the tenant, or assign themselves/any user an arbitrary data-plane role (e.g. ADMIN) in any app, by calling POST /api/public/v1/roles/assign. The endpoint only authorizes …
Budibase's OIDC SSO login links an incoming SSO identity to an existing Budibase account by email address alone, without ever checking the email_verified claim of the OIDC ID token. Budibase first tries to match the IdP sub; when that misses (any fresh attacker IdP account) it silently falls back to matching by the email claim and merges into the existing account by email, preserving that account's _id and roles. Because …
When an SSO-authenticated user tests an automation in the Budibase builder, their OAuth2 access token and refresh token are included in the automation test results. These results are broadcast via WebSocket to all builders connected to the same dev app and stored in an in-memory cache accessible to any builder who polls the test status endpoint. This allows any co-builder of the same app to steal the testing user's OAuth2 …
Budibase's MongoDB query execution endpoint (POST /api/v2/queries/:queryId) is vulnerable to NoSQL injection through user-supplied query parameters. The enrichContext() function interpolates parameter values into JSON query templates using Handlebars with noEscaping: true, then parses the result with JSON.parse(). An attacker can inject JSON metacharacters (", {, }) into parameter values to alter the structure of MongoDB queries, bypassing intended filters to read, modify, or delete arbitrary documents.
An end-user injection in Budibase's MongoDB datasource lets any BASIC app user bypass the builder's query-level access controls. Builders scope MongoDB reads per-user with bindings like {"email": "{{ currentUser.email }}"} so each app user only sees their own rows. Because the binding is handlebars-enriched into the query JSON with noEscaping: true and then JSON.parsed, Bob (a BASIC user) overrides the builder's filter with a MongoDB operator and reads every document …
The GET /api/global/groups endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag.
POST /api/v2/email on the account portal (account.budibase.app) starts an email-change workflow using a client-supplied accountId that is not validated against the authenticated session. A logged-in attacker supplies a victim's accountId and an email address they control; the verification code is delivered to the attacker's address, and completing the workflow changes the victim's account email. The attacker then password-resets the victim's account through the controlled address and logs in — full …
A builder-level user can make Budibase issue server-side HTTP requests to loopback or private-network targets by using DNS rebinding against two outbound fetch paths that are still not pinned to the validated DNS answer. The first path is OpenAPI query import. It validates the supplied hostname with the blacklist and then performs a separate raw fetch. A hostname that resolves to a public address during validation and to 127.0.0.1 during …
The Budibase AI chat-link handoff flow (GET/POST /api/chat-links/:instance/:token/handoff) binds an external chat identity (Slack/Discord/MS Teams/Telegram) to a Budibase user account. The confirmation endpoint is on a public route (no CSRF middleware, no auth-group gate) and the only credential it checks is a confirmationToken that is already rendered in plaintext into the HTML confirmation page the victim views. There is no binding between the confirmation token and the requester's Budibase session …
The login lockout mechanism in Budibase creates an observable response discrepancy that allows unauthenticated attackers to enumerate valid email addresses. When an existing user's account is locked after 5 failed login attempts, the server returns a distinct 403 response with X-Account-Locked: 1 and Retry-After: 900 headers plus the message "Account temporarily locked." For non-existing users, the response is always a generic 403 "Unauthorized" regardless of attempt count, because the lockout …
JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. The issue is a heap out-of-bounds write in the IO-streaming path and is demonstrated as a reliable process crash / denial of service. This was triaged on HackerOne as report #3785370. The issue was confirmed there and I was asked to open it here.