### 漏洞概述 **漏洞名称**: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses (CWE-776) **描述**: 多个XML解析站点在NLTK中仍使用`xml.etree.ElementTree`,这会尊重文档内部DTD子集中的``声明。一个经过精心设计的文档,几百字节的输入可以在内存中扩…
### 漏洞概述 **漏洞名称**: pathsec SSRF protection can be bypassed when a proxy is configured **漏洞类型**: 服务器端请求伪造(Server-side request forgery) **受影响组件**: `nltk.pathsec.urlopen`, `nltk.data.load`, `nltk.downloa…
### 漏洞概述 - **漏洞名称**: Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop - **CVE编号**: CVE-2026-34968 - **CWE编号**: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (Path Trav…