Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 34889+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 7.5
sigstore-js fix: verification of OID certificate extensions
github.com · 2026-07-15

### Vulnerability Overview - **Title**: verification of OID certificate extensions #1658 - **Status**: Merged - **Submitter**: bdehamer - **Merge Time**: May 23 ### Impact Scope - **Project**: sigstor…

Read more
CVSS 5.4
DSSE PAE UTF-8 Encoding Flaw Fix and POC
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves the incorrect handling of UTF-8 encoding in DSSE PAE (Pre-Authentication Encoding). Specifically, when the payload type is "application/typeUd009…

Read more
Premium intel
CVSS 7.7
Tornado AsyncHTTPClient Redirect Inconsistency and DoS Mitigation via follow_redirects/max_body_size
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves issues with the behavior of `SimpleAsyncHTTPClient` and `CurlAsyncHTTPClient` in the Tornado framework when handling redirects. Specifically: 1. …

Read more
CVSS 7.5
GHSA-52v5-j5w-gxr: sigstore certificateOIDs verification constraint bypass
github.com · 2026-07-15

# Vulnerability Overview - **Vulnerability Name**: `certificateOIDs` verification constraint is silently dropped and never enforced - **Vulnerability ID**: GHSA-52v5-j5w-gxr - **Severity**: High (CVSS…

Read more
CVSS 7.5
sigstore-js OID Certificate Extension Verification Bypass Fix
github.com · 2026-07-15

### Vulnerability Overview The provided webpage screenshot illustrates a vulnerability (issue #1658) related to the validation of certificate extensions containing Object Identifiers (OIDs). This vuln…

Read more
Premium intel
CVSS 7.7
Tornado 6.5.6 Patch: CORS Auth Header Leak & Auth Response Parsing Fix
github.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: The specific vulnerability name is not explicitly stated, but it involves multiple security-related fixes. - **Vulnerability Description**: This pa…

Read more
CVSS 7.7
Tornado SimpleAsyncHttpClient Credential Forwarding via Redirects (CVE-2024-49653) Advisory
github.com · 2026-07-15

### Vulnerability Overview **Title**: Authorization header forwarded across cross-origin redirects in SimpleAsyncHttpClient **Description**: When SimpleAsyncHttpClient follows 3xx redirects, it create…

Read more
CVSS 7.7
Tornado 6.5.6 Security Bulletin: Info Disclosure, OOB Read, and DoS Fixes
github.com · 2026-07-15

### Vulnerability Overview Tornado version 6.5.6 includes fixes for the following security-related issues: 1. **`Authorization` and `Cookie` header handling in `SimpleAsyncHTTPClient` and `CurlAsyncHT…

Read more
Premium intel
CVSS 7.5
Tornado GzipMessageDelegate DoS Vulnerability via Uncompressed Body Size Check
github.com · 2026-07-15

### Vulnerability Overview This vulnerability concerns the handling of the `max_body_size` parameter in the `GzipMessageDelegate` class within the `tornado/httpconnection.py` file. Specifically, when …

Read more
Premium intel
CVSS 7.5
Tornado AsyncHTTPClient Gzip Decompression DoS Vulnerability (CVE-2024-49855)
github.com · 2026-07-15

### Vulnerability Overview Tornado's `AsyncHTTPClient` accumulates decompressed data blocks when decompressing gzip data but does not enforce a limit on the total size of the decompressed data. This v…

Read more
CVSS 5.3
Tornado WebSocket mask Length Validation Insufficient Leading to Out-of-Bounds Read
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves insufficient validation of the length of the `mask` parameter in the `websocketchannel` module of the `tornado` library. Specifically, when the l…

Read more
Premium intel
CVSS 9.1
Fix for Path Traversal in XhmikosR/decompress Library via Symlink Validation
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves the failure to correctly validate link targets during file extraction, which may allow bypassing output directory restrictions and writing to arb…

Read more
Premium intel
CVSS 9.1
decompress npm package path traversal and setuid priv escalation CVE-2020-12269
github.com · 2026-07-15

### Vulnerability Overview **Title**: Archive extraction can create files and links outside the target directory **Description**: When extracting archive files into a directory, a maliciously crafted …

Read more
Premium intel
CVSS 9.1
Fix for archive extraction path traversal and setuid bits leak in XhmiokR/decompress
github.com · 2026-07-15

### Vulnerability Overview This vulnerability pertains to security fixes in the `XhmiokR/decompress` project, focusing on link validation, path relative control, and setuid mask handling. Specifically…

Read more
Premium intel
CVSS 9.1
Fix for archive extraction ignoring setuid/setgid/sticky bits with PoC
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves improper handling of file permission bits (such as setuid, setgid, and sticky bits) during file extraction, which may lead to potential security …

Read more
Premium intel
CVSS 9.1
decompress Path Traversal via Symlink with Shared Prefix Fix
github.com · 2026-07-15

### Vulnerability Overview This vulnerability involves a path traversal attack during file extraction, which could result in files being written to locations outside the intended output directory. Spe…

Read more
Premium intel
CVSS 9.1
Path Traversal Fix in decompress Library (CVE-2026-53486)
github.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: CVE-2026-53486 - **Vulnerability Description**: Fixes an issue where a crafted archive could read or write files outside the extraction directory. …

Read more
CVSS 6.3
NVIDIA TensorRT-LLM Vulnerable Control Sphere CWE-829 (CVE-2026-24226)
www.cve.org · 2026-07-15

### Vulnerability Overview - **CVE ID**: CVE-2026-24226 - **Description**: A vulnerability exists in NVIDIA TensorRT-LLM for Linux, which could lead to improper control of generated code. Successful e…

Read more
CVSS 6.2
NVIDIA TensorRT-LLM Unrestricted Resource Allocation Vulnerability (CVE-2026-24271) Advisory
www.cve.org · 2026-07-15

### Vulnerability Overview - **CVE ID**: CVE-2026-24271 - **Description**: NVIDIA TensorRT-LLM has a vulnerability in its OpenAI-compatible inference API, which allows an attacker to cause unlimited o…

Read more
CVSS 6.4
NVIDIA TensorRT-LLM Missing Authentication Vulnerability CVE-2026-24259 Advisory
www.cve.org · 2026-07-15

### Vulnerability Overview - **CVE ID**: CVE-2026-24259 - **Description**: A vulnerability in NVIDIA TensorRT-LLM for Linux allows an attacker to exploit a lack of authentication for critical function…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.