Search CVE reports
31 – 40 of 48904 results
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses...
1 affected package
pyjwt
| Package | 24.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks...
1 affected package
pyjwt
| Package | 24.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated...
1 affected package
pyjwt
| Package | 24.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted...
1 affected package
pyjwt
| Package | 24.04 LTS |
|---|---|
| pyjwt | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both...
1 affected package
node-ip-address
| Package | 24.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid...
1 affected package
node-ip-address
| Package | 24.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48....
1 affected package
node-ip-address
| Package | 24.04 LTS |
|---|---|
| node-ip-address | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process...
1 affected package
node-axios
| Package | 24.04 LTS |
|---|---|
| node-axios | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate...
1 affected package
node-axios
| Package | 24.04 LTS |
|---|---|
| node-axios | Needs evaluation |
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If...
1 affected package
node-axios
| Package | 24.04 LTS |
|---|---|
| node-axios | Needs evaluation |