漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
tRPC 11 WebSocket DoS Vulnerability
Vulnerability Description
tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server. Any tRPC 11 server with WebSocket enabled with a createContext method set is vulnerable. This issue has been patched in version 11.1.1.
CVSS Information
N/A
Vulnerability Type
未捕获的异常
Vulnerability Title
tRPC 安全漏洞
Vulnerability Description
tRPC是tRPC社区的一个用于构建类型安全的API的TypeScript框架。 tRPC 11.0.0版本存在安全漏洞,该漏洞源于未处理错误,可能导致WebSocket服务器崩溃。
CVSS Information
N/A
Vulnerability Type
N/A