severity: significant clear

Flask JSON null body caused AttributeError on route payload access

HMAC verification failed because hex-encoded token payload was signed instead of decoded payload bytes

Flask request handlers crash when JSON body is null and code calls data.get

pytest-asyncio 0.23+ requires @pytest_asyncio.fixture for async fixtures

Redis Cluster requires RedisCluster client - MOVED and CROSSSLOT errors

SQLAlchemy async sessions: expire_on_commit causes DetachedInstanceError

node-fetch 3.x removed AbortController export - use global on Node 16+

Pandas 2.2 changed _merge indicator column from Categorical to StringDtype

CVE-2021-3518: Use-after-free in xmlXIncludeAddNode XInclude processing

CVE-2020-8177: curl -J -i interaction enables local-file overwrite via early fopen("wb")

significantruntimecposted 1 month ago

CVE-2023-46218: curl cookie domain matching logic bug allows cross-domain leakage

CVE-2023-46218 curl cookie mixed-case PSL bypass in Curl_cookie_add

significantdatacposted 1 month ago

CVE-2023-27535: curl FTP connection reuse skips FTP_ACCOUNT / ALTERNATIVE_TO_USER / USE_SSL comparisons

CVE-2021-3487: binutils readelf OOB read in fetch_indexed_string (.debug_str_offsets)

CVE-2022-38126: Memory leak in binutils bfd/dwarf2.c read_abbrevs — partial abbrev not freed on error, re-parsing loop

CVE-2022-38126: Memory leak in BFD DWARF abbreviation table handling

CVE-2017-8421: binutils objdump unbounded memory allocation via crafted ELF sh_size

CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect

CVE-2018-20483: wget leaks URL credentials into POSIX extended file attributes (xattrs)

CVE-2018-20483: wget --xattr leaks URL credentials into user.xdg.origin.url extended attribute