Month: February 2026
CVE-2024-40725 Apache HTTP Server: source code disclosure with handlers configured via AddType
CVE-2016-3959 The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
CVE-2022-31394 Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software allowing attackers to perform HTTP2 attacks.
CVE-2024-12905 An Improper Link Resolution Before File Access (“Link Following”) and Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.
This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.
CVE-2024-34156 Stack exhaustion in Decoder.Decode in encoding/gob
Information published. Continue reading CVE-2024-34156 Stack exhaustion in Decoder.Decode in encoding/gob
