CVE-2022-32212

A vulnerability was found in NodeJS, where the IsAllowedHost check can be easily bypassed because IsIPAddress does not properly check if an IP address is invalid or not. When an invalid IPv4 address ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

(RHSA-2022:5894) Moderate: Red Hat JBoss Enterprise Application Platform 7.4.6 Security update.

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.6 is a ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security update for python-jupyterlab (important)

An update that fixes one vulnerability is now available. Description: This update for python-jupyterlab fixes the following issues: Update to 2.2.10: * Remove `form` tags' `action` attribute ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

CVE-2022-35922

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
[SECURITY] Fedora 36 Update: golang-github-gobwas-ws-1.1.0-4.fc36

Tiny WebSocket library for Go.Read More ...

Continue Reading
GO-2022-0370

Websocket client connections are vulnerable to man-in-the-middle attacks via DNS spoofing. When looking up a WSS endpoint using a DNS TXT record, the server TLS certificate is incorrectly validated u ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Undertow vulnerable to memory exhaustion due to buffer leak

Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.Read More ...

Continue Reading
[SECURITY] Fedora 35 Update: golang-github-gobwas-ws-1.1.0-3.fc35

Tiny WebSocket library for Go.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: