Search CVE reports
321 – 330 of 38395 results
Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in...
1 affected package
jupyter-server
| Package | 24.04 LTS |
|---|---|
| jupyter-server | Needs evaluation |
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses...
1 affected package
python-authlib
| Package | 24.04 LTS |
|---|---|
| python-authlib | Needs evaluation |
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
1 affected package
nodejs
| Package | 24.04 LTS |
|---|---|
| nodejs | Needs evaluation |
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to...
1 affected package
nltk
| Package | 24.04 LTS |
|---|---|
| nltk | Needs evaluation |
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration...
1 affected package
alsa-lib
| Package | 24.04 LTS |
|---|---|
| alsa-lib | Needs evaluation |
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced...
1 affected package
starlette
| Package | 24.04 LTS |
|---|---|
| starlette | Needs evaluation |
Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path}...
1 affected package
starlette
| Package | 24.04 LTS |
|---|---|
| starlette | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or...
1 affected package
python-aiohttp
| Package | 24.04 LTS |
|---|---|
| python-aiohttp | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status....
1 affected package
python-aiohttp
| Package | 24.04 LTS |
|---|---|
| python-aiohttp | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to...
1 affected package
python-aiohttp
| Package | 24.04 LTS |
|---|---|
| python-aiohttp | Needs evaluation |