Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-v859-c572-qh5p
  • Go/github.com/zitadel/zitadel
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions 5 hours ago
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-vrh8-c9cm-wh8v
  • Go/github.com/zitadel/zitadel
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange 5 hours ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-992q-9gwp-7r79
  • Go/github.com/zitadel/zitadel
ZITADEL: Auto-linking by email: IdP-side email verification is not checked 3 days ago
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-v77h-2w3m-94hx
  • Go/github.com/zitadel/zitadel
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider 3 days ago
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-w4v4-9rw7-5326
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization 4 days ago
  • Fix available
  • Severity - 7.0 (High)
GHSA-v67p-phpq-fc8x
  • Go/github.com/traefik/traefik/v3
Traefik entrypoint header-name sanitization bypassed via request trailers 4 days ago
  • Fix available
  • Severity - 7.0 (High)
GHSA-qqjf-53cj-pwvv
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik HTTP/3 Backend NTLM Connection Reuse 4 days ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-f52w-8j3h-j724
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging 4 days ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-66hp-wgxq-6f5q
  • Go/github.com/rclone/rclone
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace 4 days ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-486v-q2wf-fp2r
  • Go/github.com/rclone/rclone
rclone: http backend forwards custom/auth headers to a different host on redirect 4 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-f8g7-2xjc-7mfh
  • Go/github.com/rclone/rclone
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination 4 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-p6m2-r3w9-mpxw
  • Go/github.com/rclone/rclone
rclone local: crafted Range request against a translated symlink panics (DoS) 4 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-xwwr-4h3p-r22c
  • Go/github.com/rclone/rclone
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 4 days ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-p569-5gjg-9cmj
  • Go/github.com/rclone/rclone
rclone: RC per-server auth-proxy bypass 4 days ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-c476-6w5q-jw77
  • Go/github.com/rclone/rclone
rclone: FTP cross-session auth-proxy backend confusion 4 days ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-38xv-hf3p-h7mq
  • Go/github.com/rclone/rclone
rclone: source object names can escape the configured root on upload 4 days ago
  • Fix available
  • Severity - 5.3 (Medium)