6.1medium
Local file overwrite by extracting a malicious tar archive
Fixed in: go.podman.io/buildah/copier 1.43.4 / 1.45.1
patched
details
- Finding IDs
- F-BUILDAH-SYMLINK-001
- Status
- patched
- Fixed in
- go.podman.io/buildah/copier 1.43.4 / 1.45.1
- Recorded credit
- reporter: Oleh Konko / @1seal (alongside other reporters)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.1medium
Local file overwrite by extracting a malicious tar archive
Fixed in: go.podman.io/image/v5 5.39.3 / 5.41.2; go.podman.io/storage 1.62.1 / 1.64.1
patched
details
- Finding IDs
- F-PODMAN-001-007
- Status
- patched
- Fixed in
- go.podman.io/image/v5 5.39.3 / 5.41.2; go.podman.io/storage 1.62.1 / 1.64.1
- Recorded credit
- reporter: Oleh Konko / @1seal (alongside other reporters)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Trezor Safe improper security check in on-device display
Fixed in: Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c)
patched
details
- Finding IDs
- F-TREZOR-005
- Status
- patched
- Fixed in
- Trezor Safe 3, Safe 5, and Safe 7 (commit 70c9b0c)
- Recorded credit
- Oleh Konko / 1seal
Full sources, classification reasons and claim limits are on the finding page.
5.5medium
Verification accepts any valid Rekor entry under certain conditions
Fixed in: cosign v2.6.2, v3.0.4
patched
details
- Finding IDs
- F-SIG-036-001
- Status
- patched
- Fixed in
- cosign v2.6.2, v3.0.4
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
Fixed in: rekor 1.5.0
patched
details
- Finding IDs
- F-SIG-038-001
- Status
- patched
- Fixed in
- rekor 1.5.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Server-Side Request Forgery (SSRF) via provided public key URL
Fixed in: rekor 1.5.0
patched
details
- Finding IDs
- F-REKOR-SSRF-001
- Status
- patched
- Fixed in
- rekor 1.5.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
3.7low
Signatures considered valid with certificates that outlive expired CA certificates
Fixed in: cosign 3.0.5
patched
details
- Finding IDs
- F-COSIGN-001-003
- Status
- patched
- Fixed in
- cosign 3.0.5
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.8medium
Legacy TUF client allows for arbitrary file writes with target cache path traversal
Fixed in: sigstore 1.10.4
patched
details
- Finding IDs
- F-SIGSTORE-005
- Status
- patched
- Fixed in
- sigstore 1.10.4
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.5medium
Insufficient Verification of Data Authenticity in sigstore-js
Fixed in: @sigstore/verify 3.1.1
patched
details
- Finding IDs
- F-SIG-JS-TLOGTIME-001
- Status
- patched
- Fixed in
- @sigstore/verify 3.1.1
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
Client DoS via malformed server response
Fixed in: go-tuf/v2 2.3.1
patched
details
- Finding IDs
- F-TUF-003
- Status
- patched
- Fixed in
- go-tuf/v2 2.3.1
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
Improper validation of configured threshold for delegations
Fixed in: go-tuf/v2 2.3.1
patched
details
- Finding IDs
- F-TUF-001
- Status
- patched
- Fixed in
- go-tuf/v2 2.3.1
- Upstream @1seal credit
- @1seal: remediation_reviewer (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.1high
go-tuf TAP 4 multirepo repoName path traversal escapes local metadata cache directory
Fixed in: go-tuf/v2 2.4.1
patched
details
- Finding IDs
- F-TUF-008
- Status
- patched
- Fixed in
- go-tuf/v2 2.4.1
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.5medium
OCI image scanning could expose registry credentials
Fixed in: malcontent 1.20.3
patched
details
- Finding IDs
- F-MALCONTENT-003
- Status
- patched
- Fixed in
- malcontent 1.20.3
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.5medium
Archive extraction could write outside extraction directory
Fixed in: malcontent 1.20.3
patched
details
- Finding IDs
- F-MALCONTENT-001
- Status
- patched
- Fixed in
- malcontent 1.20.3
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Path traversal in apko dirFS allows filesystem writes outside base
Fixed in: apko (commit d8b7887)
patched
details
- Finding IDs
- F-APKO-001
- Status
- patched
- Fixed in
- apko (commit d8b7887)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
potential unbounded resource consumption in expandapk.ExpandApk on attacker-controlled .apk streams
Fixed in: apko (commit 2be3903)
patched
details
- Finding IDs
- F-APKO-007
- Status
- patched
- Fixed in
- apko (commit 2be3903)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.5medium
unbounded resource consumption in expandapk.Split on attacker-controlled .apk streams
Fixed in: apko v1.1.0
patched
details
- Finding IDs
- F-APKO-003
- Status
- patched
- Fixed in
- apko v1.1.0
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
Fixed in: apko v1.2.5
patched
details
- Finding IDs
- F-APKO-SYMLINK-001
- Status
- patched
- Fixed in
- apko v1.2.5
- Recorded credit
- reporter: @1seal
Full sources, classification reasons and claim limits are on the finding page.
6.5medium
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
Fixed in: apko v1.2.7
patched
details
- Finding IDs
- F-APKO-002
- Status
- patched
- Fixed in
- apko v1.2.7
- Recorded credit
- reporter: @1seal
Full sources, classification reasons and claim limits are on the finding page.
7.5high
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
Fixed in: apko v1.2.7
patched
details
- Finding IDs
- F-APKO-CHECKSUM-001
- Status
- patched
- Fixed in
- apko v1.2.7
- Recorded credit
- reporter: @1seal
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
Fixed in: GnuTLS 3.8.13
patched
details
- Finding IDs
- F-GNUTLS-NAMECONSTRAINTS-001
- Status
- patched
- Fixed in
- GnuTLS 3.8.13
- Recorded credit
- independently reported by Oleh Konko (1seal) and Joshua Rogers
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
Fixed in: GnuTLS 3.8.13
patched
details
- Finding IDs
- F-GNUTLS-OCSP-001
- Status
- patched
- Fixed in
- GnuTLS 3.8.13
- Recorded credit
- independently reported by Oleh Konko (1seal) and Joshua Rogers
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
Fixed in: GnuTLS 3.8.13
patched
details
- Finding IDs
- F-GNUTLS-HOSTNAME-001
- Status
- patched
- Fixed in
- GnuTLS 3.8.13
- Recorded credit
- reported by Oleh Konko (1seal)
Full sources, classification reasons and claim limits are on the finding page.
7.9high
Pipeline working-directory could allow command injection
Fixed in: melange (commit e51ca30c)
patched
details
- Finding IDs
- F-MELANGE-001
- Status
- patched
- Fixed in
- melange (commit e51ca30c)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.2high
QEMU runner could write files outside workspace directory
Fixed in: melange (commit 6e243d0d)
patched
details
- Finding IDs
- F-MELANGE-005
- Status
- patched
- Fixed in
- melange (commit 6e243d0d)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.8high
potential host command execution via license-check YAML mode patch pipeline
Fixed in: melange (commit bd132535)
patched
details
- Finding IDs
- F-MELANGE-007
- Status
- patched
- Fixed in
- melange (commit bd132535)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.5medium
path traversal in `license-path` allows reading files outside workspace
Fixed in: melange (commit 2f95c9f)
patched
details
- Finding IDs
- F-MELANGE-006
- Status
- patched
- Fixed in
- melange (commit 2f95c9f)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
cert-manager-controller DoS via Specially Crafted DNS Response
Fixed in: cert-manager v1.18.5, v1.19.3
patched
details
- Finding IDs
- F-CERTMGR-DNS-001
- Status
- patched
- Fixed in
- cert-manager v1.18.5, v1.19.3
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
script injection via sourced env file in composite action
Fixed in: trivy-action >= 0.34.0
patched
details
- Finding IDs
- F-TRIVY-ACTION-001
- Status
- patched
- Fixed in
- trivy-action >= 0.34.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
cross-origin config application via local admin API /load (caddy)
Fixed in: caddy v2.11.0
patched
details
- Finding IDs
- F-CADDY-ADMIN-LOAD-001
- Status
- patched
- Fixed in
- caddy v2.11.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.9medium
sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template annotations
Fixed in: sealed-secrets v0.36.0
patched
details
- Finding IDs
- F-SEALED-SECRETS-ROTATE-SCOPE-001
- Status
- patched
- Fixed in
- sealed-secrets v0.36.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Case-Sensitive Bypass in Connection Header Allows Removal of X-Forwarded Headers
Upstream fixed versions: Traefik: v2.11.38; Traefik: v3.6.9
patched
details
- Finding IDs
- F-TRAEFIK-003
- Status
- patched
- Fixed in
- Traefik: v2.11.38; Traefik: v3.6.9
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
TLS Handshake Error Handling Allows Stalled Connections on TCP Routers
Upstream fixed versions: Traefik: v2.11.38; Traefik: v3.6.9
patched
details
- Finding IDs
- F-TRAEFIK-004
- Status
- patched
- Fixed in
- Traefik: v2.11.38; Traefik: v3.6.9
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.7high
Kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Fixed in: v3.6.10
patched
details
- Finding IDs
- F-TRAEFIK-006
- Status
- patched
- Fixed in
- v3.6.10
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
Fixed in: AWS-LC 1.71.0
patched
details
- Finding IDs
- F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
- Status
- patched
- Fixed in
- AWS-LC 1.71.0
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
Fixed in: aws-lc-sys 0.39.0
patched
details
- Finding IDs
- F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
- Status
- patched
- Fixed in
- aws-lc-sys 0.39.0
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Path traversal in `sops exec-file --filename` leaks decrypted plaintext outside temporary directory
Fixed in: sops 3.13.0
patched
details
- Finding IDs
- F-MOZILLA-SOPS-002
- Status
- patched
- Fixed in
- sops 3.13.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
HC Vault / OpenBao token exfiltration when decrypting untrusted SOPS-encrypted files
mitigation available; configuration required
details
- Finding IDs
- F-MOZILLA-SOPS-004
- Status
- mitigation available; configuration required
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
LookupResources Cursor section tampering can crash SpiceDB process via tuple.MustParse panic
Fixed in: spicedb v1.49.1
patched
details
- Finding IDs
- F-AUTHZED-SPICEDB-001
- Status
- patched
- Fixed in
- spicedb v1.49.1
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.4medium
CRLs not considered authoritative by Distribution Point due to faulty matching logic
Fixed in: 0.104.0-alpha.5, 0.103.10
patched
details
- Finding IDs
- F-RUSTLS-WEBPKI-001
- Status
- patched
- Fixed in
- 0.104.0-alpha.5, 0.103.10
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
2.2low
Name constraints for URI names were incorrectly accepted
Fixed in: >= 0.103.12, >= 0.104.0-alpha.6
patched
details
- Finding IDs
- F-RUSTLS-WEBPKI-NAMECONSTRAINTS-URI-001
- Status
- patched
- Fixed in
- >= 0.103.12, >= 0.104.0-alpha.6
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
2.2low
Name constraints were accepted for certificates asserting a wildcard name
Fixed in: >= 0.103.12, >= 0.104.0-alpha.6
patched
details
- Finding IDs
- F-RUSTLS-WEBPKI-NAMECONSTRAINTS-WILDCARD-001
- Status
- patched
- Fixed in
- >= 0.103.12, >= 0.104.0-alpha.6
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Panic in history index request handlers when a full node runs without the history index
Fixed in: nimiq-blockchain v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-HISTORYINDEX-PANIC-001
- Status
- patched
- Fixed in
- nimiq-blockchain v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.3medium
Untrusted peer can crash address book via empty peer contact addresses
Fixed in: nimiq-network-libp2p v1.4.0
patched
details
- Finding IDs
- F-NIMIQ-DISCOVERY-EMPTY-ADDRLIST-PANIC-001
- Status
- patched
- Fixed in
- nimiq-network-libp2p v1.4.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Untrusted peer can wedge DHT
Fixed in: network-libp2p v1.4.0
patched
details
- Finding IDs
- F-NIMIQ-DHTGET-HANG-001
- Status
- patched
- Fixed in
- network-libp2p v1.4.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Peer can crash the node by opening discovery protocol substream twice
Fixed in: network-libp2p v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-DISCOVERY-DOUBLE-SUBSTREAM-PANIC-001
- Status
- patched
- Fixed in
- network-libp2p v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
nimiq-libp2p request/response codec reads entire stream before size validation
Fixed in: network-libp2p v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-REQRES-STREAMS-STALL-001
- Status
- patched
- Fixed in
- network-libp2p v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
affected
details
- Finding IDs
- F-FREEIPA-389DS-001
- Status
- affected
- Recorded credit
- Red Hat acknowledgement: Oleh Konko (1seal.org)
Full sources, classification reasons and claim limits are on the finding page.
0.0low
Request/Response inbound failure retains stale `response_channels` state after attacker-controlled failed requests
Fixed in: nimiq-network-libp2p v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-REQRES-INBOUNDLEAK-001
- Status
- patched
- Fixed in
- nimiq-network-libp2p v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Discovery peer contact book poisoning via future timestamps
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-DISCOVERY-TIMESTAMP-POISON-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
BlockInclusionProof interlink issue when hops are empty
Fixed in: nimiq-primitives v1.4.0
patched
details
- Finding IDs
- F-NIMIQ-BLOCKINCLUSIONPROOF-INTERLINK-HOPS-001
- Status
- patched
- Fixed in
- nimiq-primitives v1.4.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.4high
Malicious frontend can cause file escape outside of storage root
Fixed in: v0.28.1+
patched
details
- Finding IDs
- F-BUILDKIT-001-001
- Status
- patched
- Fixed in
- v0.28.1+
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
X.509: bypass of name constraints on wildcard SANs with matching peer names
Fixed in: >= 46.0.6
patched
details
- Finding IDs
- F-PYCA-CRYPTOGRAPHY-NAMECONSTRAINTS-WILDCARD-001
- Status
- patched
- Fixed in
- >= 46.0.6
- Recorded credit
- Reporter: 1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.1high
Sandbox skill mirroring path traversal could write outside the sandbox workspace
Fixed in: openclaw >= 2026.2.14
patched
details
- Finding IDs
- F-OPENCLAW-001
- Status
- patched
- Fixed in
- openclaw >= 2026.2.14
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.7high
create-only policy allows overwrite attempts of existing latest tag (update permission not required)
Upstream fixed versions: zot: v2.1.15
patched
details
- Finding IDs
- F-ZOT-AUTHZ-001
- Status
- patched
- Fixed in
- zot: v2.1.15
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.7high
JWKS Resolver Failure May Expose Hardcoded Default Keys
Fixed in: 1.29.1, 1.28.5, 1.27.8
patched
details
- Finding IDs
- F-ISTIO-JWKS-002
- Status
- patched
- Fixed in
- 1.29.1, 1.28.5, 1.27.8
- Recorded credit
- reported by 1seal (ISTIO-SECURITY-2026-001)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.9medium
Debug Endpoints Allow Cross-Namespace Proxy Data Access
Fixed in: 1.29.1, 1.28.5, 1.27.8
patched
details
- Finding IDs
- F-ISTIO-XDSDEBUG-002
- Status
- patched
- Fixed in
- 1.29.1, 1.28.5, 1.27.8
- Recorded credit
- reported by 1seal (ISTIO-SECURITY-2026-001)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.0medium
SSRF via RequestAuthentication jwksUri
Fixed in: 1.29.2, 1.28.6
patched
details
- Finding IDs
- F-ISTIO-JWKS-001
- Status
- patched
- Fixed in
- 1.29.2, 1.28.6
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Nested archive extraction failure can drop content from scan inputs
Fixed in: malcontent v1.21.0
patched
details
- Finding IDs
- F-MALCONTENT-010
- Status
- patched
- Fixed in
- malcontent v1.21.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
9.6critical
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
Fixed in: v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2
patched
details
- Finding IDs
- F-TEKTON-001-001
- Status
- patched
- Fixed in
- v1.0.1, v1.3.3, v1.6.1, v1.9.2, v1.10.2
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation
Fixed in: wolfSSL 5.9.0
patched
details
- Finding IDs
- F-WOLFSSL-ALPN-001
- Status
- patched
- Fixed in
- wolfSSL 5.9.0
- Recorded credit
- thanks to Oleh Konko (1seal) for the report (wolfSSL v5.9.0-stable release note)
Full sources, classification reasons and claim limits are on the finding page.
8.3high
ECH parsing heap buffer overflow
Fixed in: wolfSSL 5.9.0
patched
details
- Finding IDs
- F-WOLFSSL-ECH-001
- Status
- patched
- Fixed in
- wolfSSL 5.9.0
- Recorded credit
- thanks to Oleh Konko (1seal) for testing (wolfSSL v5.9.0-stable release note)
Full sources, classification reasons and claim limits are on the finding page.
7.0high
URI nameConstraints not enforced in ConfirmNameConstraints()
Fixed in: wolfSSL 5.9.1
patched
details
- Finding IDs
- F-WOLFSSL-NC-URI-001
- Status
- patched
- Fixed in
- wolfSSL 5.9.1
- Recorded credit
- finder: Oleh Konko @1seal (wolfSSL CNA / v5.9.1-stable release note)
Full sources, classification reasons and claim limits are on the finding page.
6.5medium
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
Upstream fixed versions: github.com/tektoncd/pipeline: 1.0.1, 1.3.3, 1.6.1, 1.9.2, 1.10.2
patched
details
- Finding IDs
- F-TEKTON-PANIC-001
- Status
- patched
- Fixed in
- github.com/tektoncd/pipeline: 1.0.1, 1.3.3, 1.6.1, 1.9.2, 1.10.2
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.5medium
VerificationPolicy regex pattern bypass via substring matching
Upstream fixed versions: github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1
patched
details
- Finding IDs
- F-TEKTON-REGEX-001
- Status
- patched
- Fixed in
- github.com/tektoncd/pipeline: 1.0.2, 1.3.4, 1.6.2, 1.9.3, 1.11.1
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Error-path cleanup gap can leak scanners and fds and degrade availability
Fixed in: malcontent v1.21.0
patched
details
- Finding IDs
- F-MALCONTENT-006
- Status
- patched
- Fixed in
- malcontent v1.21.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.1high
Missing proposal body root verification
Fixed in: nimiq-blockchain v1.2.2
patched
details
- Finding IDs
- F-NIMIQ-TENDERMINT-001
- Status
- patched
- Fixed in
- nimiq-blockchain v1.2.2
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.9medium
Macro block proposal interlink bug
Fixed in: nimiq-blockchain v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-INTERLINK-001
- Status
- patched
- Fixed in
- nimiq-blockchain v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.8medium
`UpdateValidator` transactions allows voting key change without proof-of-knowledge
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-ROGUEKEY-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
3.1low
Panic via `HistoryTreeProof` length mismatch
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-HISTORYPROOF-PANIC-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Peer-triggerable panic during history sync
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-HISTORYSYNC-PANIC-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Peer-triggerable crash via invalid election macro validators voting key hashing announced macro blocks
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-VALIDATORSKEY-PANIC-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Vesting insufficient funds error can panic
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-VESTING-MINCAP-UNDERFLOW-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
9.6critical
skip block quorum bypass via out-of-range BitSet indices + u16 truncation
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-SKIPBLOCK-QUORUMBYPASS-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.2high
tar archive path traversal in build context extraction allows writing files outside destination directory
Upstream fixed versions: package name not specified: no patched version listed
unpatched
details
- Finding IDs
- F-CHAINGUARD-FORKS-KANIKO-AG5-001
- Status
- unpatched
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.3medium
unbounded HTTP download in `melange update-cache` can exhaust disk in CI
Upstream fixed versions: package name not specified: v0.43.4
patched
details
- Finding IDs
- F-MELANGE-003
- Status
- patched
- Fixed in
- package name not specified: v0.43.4
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
6.1medium
Path traversal in melange's external pipeline resolver (pipeline[].uses) allows loading a pipeline from outside the pipeline directories
Fixed in: melange v0.43.4
patched
details
- Finding IDs
- F-MELANGE-008
- Status
- patched
- Fixed in
- melange v0.43.4
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.4medium
Path traversal in melange --persist-lint-results via unvalidated .PKGINFO fields
Fixed in: melange v0.43.4
patched
details
- Finding IDs
- F-MELANGE-004
- Status
- patched
- Fixed in
- melange v0.43.4
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Workspace trust for MCP servers
Fixed in: VS Code 1.109.1
patched
details
- Finding IDs
- F-VSCODE-MCP-001
- Status
- patched
- Fixed in
- VS Code 1.109.1
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
Full sources, classification reasons and claim limits are on the finding page.
8.0high
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
Fixed in: VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1
patched
details
- Finding IDs
- F-VSCODE-COPILOT-001
- Status
- patched
- Fixed in
- VS Code 1.110.1; VS Code Copilot Chat Extension 0.37.1
- Recorded credit
- MSRC acknowledgement: Oleh Konko with 1seal
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
Fixed in: upstream commit 4f28b87fdd24
patched
details
- Finding IDs
- F-QEMU-001-001
- Status
- patched
- Fixed in
- upstream commit 4f28b87fdd24
- Recorded credit
- Reported-by: Oleh Konko <https://github.com/1seal>
Full sources, classification reasons and claim limits are on the finding page.
8.8high
AuthZ plugin bypass with oversized request body
Upstream fixed versions: Docker Engine: 29.3.1
patched
details
- Finding IDs
- F-MOBY-001-001
- Status
- patched
- Fixed in
- Docker Engine: 29.3.1
- Recorded credit
- 1seal / Oleh Konko (@1seal)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Pull-through cache credential exfiltration via www-authenticate bearer realm
Upstream fixed versions: distribution: >=3.1.0
patched
details
- Finding IDs
- F-DIST-PROXY-SSRF-001
- Status
- patched
- Fixed in
- distribution: >=3.1.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Stale blob access resurrection via repo-scoped redis descriptor cache invalidation
Upstream fixed versions: package name not specified: >=3.1.0
patched
details
- Finding IDs
- F-DIST-REDIS-REVIVAL-001
- Status
- patched
- Fixed in
- package name not specified: >=3.1.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
Upstream fixed versions: go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0
patched
details
- Finding IDs
- F-OTELGO-001
- Status
- patched
- Fixed in
- go.opentelemetry.io/otel/baggage: v1.41.0; go.opentelemetry.io/otel/propagation: v1.41.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
OTLP HTTP exporters read unbounded HTTP response bodies
Upstream fixed versions: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp: v0.19.0
patched
details
- Finding IDs
- F-OTELGO-002
- Status
- patched
- Fixed in
- go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp: v1.43.0; go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp: v0.19.0
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
OTLP exporter reads unbounded HTTP response bodies
Fixed in: 1.15.2
patched
details
- Finding IDs
- F-OTELGO-002
- Status
- patched
- Fixed in
- 1.15.2
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
Fixed in: go1.26.2
patched
details
- Finding IDs
- F-GO-X509-WILDCARD-CASE-001
- Status
- patched
- Fixed in
- go1.26.2
- Recorded credit
- public credit to @1seal in golang/go#78332
Full sources, classification reasons and claim limits are on the finding page.
4.8medium
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Fixed in: 3.20.2, 4.1.4
patched
details
- Finding IDs
- F-HELM-UNTAR-ROOT-COLLAPSE-001
- Status
- patched
- Fixed in
- 3.20.2, 4.1.4
- Recorded credit
- Oleh Konko (@1seal)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
3.7low
Index out-of-bounds panic via crafted AK certificate with empty EKU in TPM device attestation
Fixed in: v0.30.0
patched
details
- Finding IDs
- F-SMALLSTEP-AK-EKU-001
- Status
- patched
- Fixed in
- v0.30.0
- Recorded credit
- Oleh Konko (@1seal)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Remote crash via off-by-one signer bounds check in proposal buffer
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-PROPOSAL-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Panic via RequestMacroChain micro-block locator
Fixed in: v1.3.0
patched
details
- Finding IDs
- F-NIMIQ-MACROCHAIN-001
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.1high
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
Fixed in: 1.16.4
patched
details
- Finding IDs
- F-KYVERNO-APICALL-001
- Status
- patched
- Fixed in
- 1.16.4
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
9.8critical
Heap out-of-bounds write in tiano decompressor `ReadCLen`
Fixed in: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
patched
details
- Finding IDs
- F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003
- Status
- patched
- Fixed in
- CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
9.8critical
Stack out-of-bounds write in tiano decompressor MakeTable
Fixed in: CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
patched
details
- Finding IDs
- F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
- Status
- patched
- Fixed in
- CVE record: 1.14; GHSA: 1.13 (conflicting version metadata)
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.1medium
Inconsistent negation behavior between in-toto-golang and in-toto-python
Fixed in: in-toto-golang v0.11.0
patched
details
- Finding IDs
- F-INTOTO-CROSS-IMPL-001
- Status
- patched
- Fixed in
- in-toto-golang v0.11.0
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
Fixed in: 2.0.0, 1.21.5, 1.20.10, 1.19.16
patched
details
- Finding IDs
- F-VAULT-AUTHZ-BEARER-TOKEN-LEAK-001
- Status
- patched
- Fixed in
- 2.0.0, 1.21.5, 1.20.10, 1.19.16
- Recorded credit
- identified and reported by Oleh Konko of 1seal (HCSEC-2026-07)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Fixed in: Vault CE 2.0.0; Vault Enterprise 2.0.0, 1.21.5, 1.20.10, 1.19.16
patched
details
- Finding IDs
- F-VAULT-ACME-SSRF-001
- Status
- patched
- Fixed in
- Vault CE 2.0.0; Vault Enterprise 2.0.0, 1.21.5, 1.20.10, 1.19.16
- Recorded credit
- independently identified and reported by Oleh Konko of 1seal (HCSEC-2026-06)
Full sources, classification reasons and claim limits are on the finding page.
7.7high
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Fixed in: 26.2.14, 26.4.10, 26.5.5, 26.6.0
patched
details
- Finding IDs
- F-KEYCLOAK-SAML-001
- Status
- patched
- Fixed in
- 26.2.14, 26.4.10, 26.5.5, 26.6.0
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
4.7medium
Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
Fixed in: 3.3.1, 4.0.5
patched
details
- Finding IDs
- F-AWS-ENCRYPTION-SDK-PYTHON-001
- Status
- patched
- Fixed in
- 3.3.1, 4.0.5
- Recorded credit
- acknowledgement: 1seal.org
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
Full sources, classification reasons and claim limits are on the finding page.
7.7high
Memory Corruption in event-stream parsing of headers
Fixed in: aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764
patched
details
- Finding IDs
- F-AWS-EVENT-STREAM-001
- Status
- patched
- Fixed in
- aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764
- Recorded credit
- acknowledgement: Oleh Konko from 1seal / 1seal.org
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Fixed in: aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory
patched
details
- Finding IDs
- F-AWS-SDK-GO-V2-ES-001
- Status
- patched
- Fixed in
- aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory
- Recorded credit
- reporter: @1seal (accepted); AWS acknowledgement: Oleh Konko (@1seal)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.3medium
Signature Threshold Bypass in awslabs/tough Delegated Roles
Fixed in: tough 0.22.0, tuftool 0.15.0
patched
details
- Finding IDs
- F-AWS-TOUGH-001
- Status
- patched
- Fixed in
- tough 0.22.0, tuftool 0.15.0
- Recorded credit
- reporter: @1seal; acknowledgement: Oleh Konko of 1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
Missing Delegated Metadata Validation in awslabs/tough
Fixed in: tough 0.22.0, tuftool 0.15.0
patched
details
- Finding IDs
- F-AWS-TOUGH-002 / F-AWS-TOUGH-003 / F-AWS-TOUGH-004 / F-AWS-TOUGH-005
- Status
- patched
- Fixed in
- tough 0.22.0, tuftool 0.15.0
- Recorded credit
- reporter: @1seal; acknowledgement: Oleh Konko of 1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
Multiple Path Traversal Variants in awslabs/tough
Fixed in: tough 0.22.0, tuftool 0.15.0
patched
details
- Finding IDs
- F-AWS-TOUGH-007 / F-AWS-TOUGH-008 / F-AWS-TOUGH-009
- Status
- patched
- Fixed in
- tough 0.22.0, tuftool 0.15.0
- Recorded credit
- reporter: @1seal; acknowledgement: Oleh Konko of 1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
rxrpc: Fix RxGK token loading to check bounds
Fixed in: Linux kernel upstream
patched
details
- Finding IDs
- F-TORVALDS-LINUX-RXRPC-001
- Status
- patched
- Fixed in
- Linux kernel upstream
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
Fixed in: Linux kernel upstream
patched
details
- Finding IDs
- F-TORVALDS-LINUX-TIPC-001
- Status
- patched
- Fixed in
- Linux kernel upstream
Full sources, classification reasons and claim limits are on the finding page.
7.6high
bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data
Fixed in: main PR #104913, v4.3 PR #108335; v3.7 backport pending
patched
details
- Finding IDs
- F-ZEPHYR-BLE-001
- Status
- patched
- Fixed in
- main PR #104913, v4.3 PR #108335; v3.7 backport pending
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Bearer realm URL not validated, enabling SSRF to internal networks and TLS downgrade
Fixed in: oras-go v2.7.0
patched
details
- Finding IDs
- F-ORAS-AUTH-001
- Status
- patched
- Fixed in
- oras-go v2.7.0
- Recorded credit
- @1seal credited as Analyst; advisory says reported by bugbunny.ai
- Upstream @1seal credit
- @1seal: analyst (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
credential forwarding via unvalidated Location header in oras-go blob upload
Upstream fixed versions: https://github.com/oras-project/oras-go: v2.6.2
patched
details
- Finding IDs
- F-ORAS-LOCATION-UPLOAD-001
- Status
- patched
- Fixed in
- https://github.com/oras-project/oras-go: v2.6.2
- Recorded credit
- reporter: @1seal
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
7.5high
io.element.call deeplink allows attacker-controlled HTTPS origin and may grant mic/camera to that origin
Fixed in: Element X iOS 26.05.0
CVE-2026-55644: RESERVED; not counted as a published CVE
patched
details
- Finding IDs
- F-ELEMENTX-IOS-001
- Status
- patched
- Fixed in
- Element X iOS 26.05.0
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
Full sources, classification reasons and claim limits are on the finding page.
5.9medium
Abnormal process termination in DNS UDP filter
Fixed in: Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2
patched
details
- Finding IDs
- F-ENVOY-001-002
- Status
- patched
- Fixed in
- Envoy 1.35.12, 1.36.8, 1.37.4, 1.38.2
- Recorded credit
- finder: @1seal
- Upstream @1seal credit
- @1seal: finder (accepted)
Full sources, classification reasons and claim limits are on the finding page.
8.8high
Bluetooth: SMP: force responder MITM requirements before building the pairing response
Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7
patched
details
- Finding IDs
- F-TORVALDS-LINUX-BT-SMP-001
- Status
- patched
- Fixed in
- Linux 7.0; stable backports listed in the CNA record; mainline d05111bfe37bfd8bd4d2dfe6675d6bdeef43f7c7
- Recorded credit
- Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.
Full sources, classification reasons and claim limits are on the finding page.
8.8high
Bluetooth: SMP: derive legacy responder STK authentication from MITM state
Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe
patched
details
- Finding IDs
- F-TORVALDS-LINUX-BT-SMP-001
- Status
- patched
- Fixed in
- Linux 7.0; stable backports listed in the CNA record; mainline 20756fec2f0108cb88e815941f1ffff88dc286fe
- Recorded credit
- Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.
Full sources, classification reasons and claim limits are on the finding page.
8.1high
Bluetooth: hci_event: move wake reason storage into validated event handlers
Fixed in: Linux 7.0; stable backports listed in the CNA record; mainline 2b2bf47cd75518c36fa2d41380e4a40641cc89cd
patched
details
- Finding IDs
- F-TORVALDS-LINUX-BT-HCI-001
- Status
- patched
- Fixed in
- Linux 7.0; stable backports listed in the CNA record; mainline 2b2bf47cd75518c36fa2d41380e4a40641cc89cd
- Recorded credit
- Upstream commit author and Signed-off-by: Oleh Konko / 1seal; no credit field in the Linux CNA record.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
file store write outside workingDir via symlink traversal in oras-go
Fixed in: CVE record: 2.6.1; GHSA: 2.6.2 (conflicting version metadata)
patched
details
- Finding IDs
- F-ORAS-SYMLINK-WRITE-001
- Status
- patched
- Fixed in
- CVE record: 2.6.1; GHSA: 2.6.2 (conflicting version metadata)
- Recorded credit
- reporter: @1seal (accepted, repository GHSA)
- Upstream @1seal credit
- @1seal: reporter (accepted)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject malformed ReplaceOp payloads without a panic
merged
details
- Finding IDs
- F-COSIGN-003
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
docs: clarify file_server hide case-sensitivity
merged
details
- Finding IDs
- F-CADDY-FILESERVER-HIDE-CASE-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Cap request body size in submission proxy
merged
details
- Finding IDs
- F-CTGO-S2A-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
docs: clarify proxy cache trust boundary for upstream token-service discovery
merged
details
- Finding IDs
- F-HARBOR-REALM-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
acmeserver: warn when policy rules unset
merged
details
- Finding IDs
- F-CADDY-ACME-POLICY-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
More validation of delegated OCSP responders
merged
details
- Finding IDs
- F-CADDY-CERTMAGIC-OCSP-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
ocsp: add delegated responder authorization regression test
merged
details
- Finding IDs
- F-CADDY-CERTMAGIC-OCSP-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
set explicit http server timeouts
Fixed in: v1.3.3
merged
details
- Finding IDs
- F-CTGO-TIMEOUT-001
- Status
- merged
- Fixed in
- v1.3.3
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
remote crash in rekor response handling via unsafe e.body.(string) type assertion
merged
details
- Finding IDs
- F-COSIGN-005
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
remote crash in policy evaluation via unsafe attestation payload type assertion
merged
details
- Finding IDs
- F-COSIGN-006
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
bundle parsing dos via unbounded tlogentries
closed unmerged
details
- Finding IDs
- F-SIG-GO-000-001
- Status
- closed unmerged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
nil pointer dereference in publickey() via malformed pem
merged
details
- Finding IDs
- F-SIG-GO-004
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
remote crash in online tlog verification via nil pointer dereference in verifytlogentryoffline
merged
details
- Finding IDs
- F-COSIGN-004
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
timestamp response verification accepts revoked tsa certificate (no crl/ocsp checking)
merged
details
- Finding IDs
- F-TSA-001-002
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
ntp drift does not gate timestamp issuance
merged
details
- Finding IDs
- F-SIG-040-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
tlog entry validation fail-open (rekor v2 protojson parsing)
merged
details
- Finding IDs
- F-SIG-004-002
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
certificate identity regex not auto-anchored enables identity policy bypass
merged
details
- Finding IDs
- F-SIG-016-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
docs(crd): clarify ctlog:{} disables tlog verification
open
details
- Finding IDs
- F-SIG-034-001
- Status
- open
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
rfc3161 timestamp verification accepts revoked tsa certificate (no crl/ocsp checking)
merged
details
- Finding IDs
- F-SIG-014-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
security hardening: relabel perf/dos guard
merged
details
- Finding IDs
- F-PROMETHEUS-RELABEL-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
feat(ngclient): require explicit bootstrap argument
merged
details
- Finding IDs
- F-TUF-PYTUF-002
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix OSSL_parse_url userinfo scan to respect authority boundary
applied upstream
details
- Finding IDs
- F-OPENSSL-NC-URI-AUTHORITY-001
- Status
- applied upstream
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
x509: reject unauthorized stapled OCSP response signers
applied upstream
details
- Finding IDs
- F-OPENSSL-OCSP-001
- Status
- applied upstream
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Forbid GEN_OTHERNAME SMTP UTF8 email name constraints.
applied upstream
details
- Finding IDs
- F-OPENSSL-NC-SMTPUTF8MAILBOX-001
- Status
- applied upstream
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
pki/acme: reject unsafe validation targets during challenge verification
enterprise merged
details
- Finding IDs
- F-VAULT-ACME-SSRF-001
- Status
- enterprise merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject crls with unrecognized critical extensions
merged
details
- Finding IDs
- F-WOLFSSL-CRL-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
cms: Reject AES-256-CBC IV with invalid length
merged
details
- Finding IDs
- F-NITRO-IVLEN-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Add a warning when TLS isn't enabled for Hubble Relay
merged to main/pre-release only
details
- Finding IDs
- F-CILIUM-001-002
- Status
- merged to main/pre-release only
- Recorded credit
- Reported by @1seal
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
docker fetcher: strip sensitive headers on descriptor URLs
merged
details
- Finding IDs
- F-CONTAINERD-DESCURLS-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix: enforce timeout on external data provider requests
merged
details
- Finding IDs
- F-GK-EXT-001
- Status
- merged
- Recorded credit
- thanks @1seal for raising the issue
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
srtpkdf input bounds checking
applied upstream
details
- Finding IDs
- F-OPENSSL-SRTPKDF-002
- Status
- applied upstream
- Recorded credit
- reported by https://github.com/1seal (merged from #30001)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
hardening: minimum threshold for withintegratedtimestamps
merged
details
- Finding IDs
- F-SIG-GO-THRESHOLD-001
- Status
- merged
- Recorded credit
- thanks @1seal for reporting this improvement
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Don't modify http.DefaultTransport
merged
details
- Finding IDs
- F-BOULDER-009
- Status
- merged
- Recorded credit
- thanks to Oleh Konko (@1seal) for reporting this issue (comment by @aarongable).
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Apply hardening fixes from upstream Tiano implementation
merged
details
- Finding IDs
- F-UEFI-FIRMWARE-TIANO-READCLEN-OOBW-003 / F-UEFI-FIRMWARE-TIANO-MAKETABLE-OOBW-002
- Status
- merged
- Recorded credit
- PR body: "Thank you @1seal for mentioning this!"
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Type assert the entry bundle when verifying inclusion proof
merged
details
- Finding IDs
- F-REKOR-VERIFY-002
- Status
- merged
- Recorded credit
- PR body: "Thanks to @1seal for reporting this."
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
http_challenge SSRF fixed in v1.14.2 and v1.13.4
released
details
- Finding IDs
- F-SPIRE-HTTPCHALLENGE-001
- Status
- released
- Recorded credit
- Thank you, Oleh Konko (@1seal) for reporting this issue. also credited in v1.13.4 and CHANGELOG.md.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
[release/2.1] update to Go 1.25.9, 1.26.2
merged
details
- Finding IDs
- F-GO-X509-WILDCARD-CASE-001
- Status
- merged
- Recorded credit
- PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
[release/2.2] update to Go 1.25.9, 1.26.2
merged
details
- Finding IDs
- F-GO-X509-WILDCARD-CASE-001
- Status
- merged
- Recorded credit
- PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment
released
details
- Finding IDs
- F-HELM-UNTAR-ROOT-COLLAPSE-001
- Status
- released
- Recorded credit
- v4.1.4 release note thanks @1seal among the reporters.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
chore: update to Go 1.25.9, 1.26.9
merged
details
- Finding IDs
- F-GO-X509-WILDCARD-CASE-001
- Status
- merged
- Recorded credit
- PR body includes @1seal in the upstream Go security credit text for Go 1.25.9 / 1.26.2.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
merged
details
- Finding IDs
- F-GO-X509-WILDCARD-CASE-001
- Status
- merged
- Recorded credit
- PR body includes @1seal in the upstream Go security credit text for Go 1.26.2.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Rewrite constraint matching to avoid permissive catch-all branch
merged
details
- Finding IDs
- F-RUSTLS-WEBPKI-001
- Status
- merged
- Recorded credit
- PR description says it addresses an issue privately reported by @1seal.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Disallow wildcard partial domains when using MatchDomainName.
merged
details
- Finding IDs
- F-WOLFSSL-NC-WILDCARD-001
- Status
- merged
- Recorded credit
- PR body says: Thanks to Oleh Konko for the report.
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Global executable ownership check accepts a prefix-colliding package directory
Fixed in: bin-links 6.0.1; also verified in npm 11.15.0 (bin-links 6.0.2)
fixed publicly
details
- Finding IDs
- F-NPM-CLI-001
- Status
- fixed publicly
- Fixed in
- bin-links 6.0.1; also verified in npm 11.15.0 (bin-links 6.0.2)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Deployment branch text is reinterpreted as Git command arguments
Fixed in: main and 4.0.0-canary-6848; stable 3.10.2 still uses the old command path
merged to main/pre-release only
details
- Finding IDs
- F-DOCUSAURUS-DEPLOY-ARGINJECT-001
- Status
- merged to main/pre-release only
- Fixed in
- main and 4.0.0-canary-6848; stable 3.10.2 still uses the old command path
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Binary HTTP field-section length includes its own prefix
Fixed in: main fix commit; v2026.09.21.00 still contains the old parser
fixed on main (release not confirmed)
details
- Finding IDs
- F-PROXYGEN-BINARYHTTP-001
- Status
- fixed on main (release not confirmed)
- Fixed in
- main fix commit; v2026.09.21.00 still contains the old parser
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Snapshot transport accepts file paths outside its destination root
Fixed in: public source commit; a separate fixed release is not established
fixed on main (release not confirmed)
details
- Finding IDs
- F-WHATSAPP-WARAFT-001
- Status
- fixed on main (release not confirmed)
- Fixed in
- public source commit; a separate fixed release is not established
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Exported activity accepts actions intended for internal VPN widgets
Fixed in: 5.19.72.0 source and release; installed store binaries not reverified
fixed publicly
details
- Finding IDs
- F-PROTON-VPN-ANDROID-GLANCE-001
- Status
- fixed publicly
- Fixed in
- 5.19.72.0 source and release; installed store binaries not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Authenticator processes OTP deep links before completing local authentication
Fixed in: 1.4.0 source tag; App Store delivery not independently verified
fixed publicly
details
- Finding IDs
- F-PROTON-IOS-AUTH-001
- Status
- fixed publicly
- Fixed in
- 1.4.0 source tag; App Store delivery not independently verified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Deep-link upload path omits external URI validation
Fixed in: 2.40.0 source tag; also present in the later 3.0.0 source release
fixed publicly
details
- Finding IDs
- F-PROTON-DRIVE-DEEPLINK-001
- Status
- fixed publicly
- Fixed in
- 2.40.0 source tag; also present in the later 3.0.0 source release
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Recovery and wallet import logging includes mnemonic words
Fixed in: v1.3.0+115 source tag; store rollout not independently verified
fixed publicly
details
- Finding IDs
- F-PROTON-WALLET-FLUTTER-001
- Status
- fixed publicly
- Fixed in
- v1.3.0+115 source tag; store rollout not independently verified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Ambiguous multi-at-sign mailbox evades excluded email name constraints
Fixed in: Java 1.85 and C# 2.7.0, with default strict email-name parsing
fixed publicly
details
- Finding IDs
- F-BC-NC-MULTIAT-001
- Status
- fixed publicly
- Fixed in
- Java 1.85 and C# 2.7.0, with default strict email-name parsing
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Model tensor dimension count can exceed a four-element stack array
Fixed in: verified in v1.9.4; not asserted to be the first fixed version
fixed publicly
details
- Finding IDs
- F-WHISPER-001-002
- Status
- fixed publicly
- Fixed in
- verified in v1.9.4; not asserted to be the first fixed version
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Notary-sponsored transaction fees are not bounded by the individual payer deposit
Fixed in: v3.10.1; network deployment not independently verified
fixed publicly
details
- Finding IDs
- F-NEO-NOTARY-001
- Status
- fixed publicly
- Fixed in
- v3.10.1; network deployment not independently verified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Failed message verification logs received and computed authentication tags
Fixed in: v0.103.0 library release; downstream application rollout not established
fixed publicly
details
- Finding IDs
- F-LIBSIGNAL-MAC-LOG-001
- Status
- fixed publicly
- Fixed in
- v0.103.0 library release; downstream application rollout not established
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Configuration loader builds a path before validating the tunnel name
Fixed in: v1.1; recorded as defensive validation, not a confirmed reachable exploit
fixed publicly
details
- Finding IDs
- F-WIREGUARD-001-001
- Status
- fixed publicly
- Fixed in
- v1.1; recorded as defensive validation, not a confirmed reachable exploit
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
bound preimage writes by the output buffer capacity
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-BTC-PREIMAGE-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
correct an off-by-one move in BIP32 derivation parsing
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-BTC-BIP32-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject empty chunks in streamed preimage handling
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-BTC-USTREAM-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject a derivation step at the array capacity boundary
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-BTC-OBO-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject all negative merkleized-map return values before using their length
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-BTC-NEGRC-002
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
clear MuSig nonce-related buffers on error paths
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-BTC-MUSIG-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
enforce the collection capacity before adding a data-path element
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-ETH-GCS-COLLECTION-OOBWRITE-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
preserve chunk offsets while parsing RLP chain ID and nonce
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-ETH-USTREAM-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject truncated calldata sizes and offsets in generic clear signing
fixed in public source; rollout not reverified
details
- Finding IDs
- F-LEDGER-ETH-GCS-U16-OFFSET-SPLICE-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject malformed ACME external-account-binding protected fields without a panic
fixed in public source; rollout not reverified
details
- Finding IDs
- F-VAULT-ACME-EAB-PANIC-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
avoid ciphertext-sized stack allocation in CMS decryption
fixed in public source; rollout not reverified
details
- Finding IDs
- F-NITRO-CMS-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
validate the region name supplied by an S3 redirect
fixed in public source; rollout not reverified
details
- Finding IDs
- F-AWS-CLI-BOTOCORE-S3SSRF-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
create TUF cache directories with restrictive permissions
fixed in public source; rollout not reverified
details
- Finding IDs
- F-TUF-002
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
limit webhook interceptor request bodies before reading them
fixed in public source; rollout not reverified
details
- Finding IDs
- F-ARGOPROJ-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
reject grouping file-exporter traversal through Windows path separators
fixed in public source; rollout not reverified
details
- Finding IDs
- F-OTELCOLLECTORCONTRIB-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
bound the verify endpoint request body
Fixed in: v0.29.0
fixed publicly
details
- Finding IDs
- F-HEADSCALE-001-002
- Status
- fixed publicly
- Fixed in
- v0.29.0
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
check reflector peer-tag length before subtracting the header size
partially fixed publicly
details
- Finding IDs
- F-TGDESKTOP-REFLECTOR-001
- Status
- partially fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
validate the boot image buffer across the syscall boundary
fixed in public source; rollout not reverified
details
- Finding IDs
- F-TREZOR-012
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
check transport progress-token length before allocating the payload buffer
partially fixed publicly
details
- Finding IDs
- F-TELEGRAM-OOM-001
- Status
- partially fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
avoid negative sample offsets in animated AVIF decoding
Fixed in: Firefox 150 (vendor tracker status)
fixed publicly
details
- Finding IDs
- F-FIREFOX-AVIF-MP4PARSE-OFFSET-001
- Status
- fixed publicly
- Fixed in
- Firefox 150 (vendor tracker status)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
remove the GitHub preview webhook and its deployment configuration
feature removed publicly
details
- Finding IDs
- F-SKAFFOLD-WEBHOOK-001
- Status
- feature removed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
JSON injection in Mini App custom method response enables arbitrary JavaScript execution in WebAppWebView
fixed publicly
details
- Finding IDs
- F-TELEGRAM-JSBRIDGE-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Non-Constant-Time Message Key Comparison in Secret Chat Decryption Violates Security Guidelines
fixed publicly
details
- Finding IDs
- F-TELEGRAM-E2E-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
WKWebView payment bridge accepts payment_form_submit from untrusted subframes without frame validation
fixed publicly
details
- Finding IDs
- F-TELEGRAM-IOS-BOTPAY-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Telegram iOS Web App bridge exposed to third-party iframes
fixed publicly
details
- Finding IDs
- F-TELEGRAM-WEBAPP-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
heap buffer over-read in TL deserialization from operator precedence bug
fixed publicly
details
- Finding IDs
- F-TELEGRAM-TL-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Bluetooth: hci_event: move wake reason storage into validated event handlers
merged
details
- Finding IDs
- F-TORVALDS-LINUX-BT-HCI-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
merged
details
- Finding IDs
- F-TORVALDS-LINUX-TIPC-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Bluetooth: SMP: force responder MITM requirements before building the pairing response
merged
details
- Finding IDs
- F-TORVALDS-LINUX-BT-SMP-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
WebGPU presentation sizing hardening after integer-overflow report
fixed publicly
details
- Finding IDs
- F-MOZILLA-FIREFOX-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Push IPC observer path removed after bug 2022681 report
fixed publicly
details
- Finding IDs
- F-FIREFOX-IPC-PUSH-012
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
[confighttp] Enforce max_request_body_size before snappy decompression
fixed publicly in v0.152.0
details
- Finding IDs
- F-OTELCOLLECTOR-001
- Status
- fixed publicly in v0.152.0
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
docs: be explicit about artifact security
merged
details
- Finding IDs
- F-ARGO-ARTIFACT-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Do not allow empty hashes for the Target role
merged
details
- Finding IDs
- F-TUF-009
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Validate healthcheck path configuration
merged
details
- Finding IDs
- F-TRAEFIK-002
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Reject absolute URL in healthcheck path configuration
merged
details
- Finding IDs
- F-TRAEFIK-002
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
bound request-body reads in the machine map endpoint
fixed publicly
details
- Finding IDs
- F-HEADSCALE-001-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
XDS debug endpoints to require authentication
fixed publicly with release-note credit
details
- Finding IDs
- F-ISTIO-001
- Status
- fixed publicly with release-note credit
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix cross-namespace access in statusgen xds debug endpoints
fixed publicly with release-note credit
details
- Finding IDs
- F-ISTIO-XDS-DEBUG-001
- Status
- fixed publicly with release-note credit
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix: reject certs with literal-IP CN and no SAN
merged
details
- Finding IDs
- F-AWS-S2N-TLS-IP-CN-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix CN fallback handling in name constraints checking
fixed publicly
details
- Finding IDs
- F-AWS-LC-NAMECONSTRAINTS-001 / F-AWS-LC-NAMECONSTRAINTS-002
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
hyperv/syndbg: check length returned by cpu_physical_memory_map()
merged
details
- Finding IDs
- F-QEMU-001-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
pin github actions versions
fixed publicly
details
- Finding IDs
- F-AWS-ROLESANYWHERE-GHA-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix SHA pinning: use correct SHAs matching original action versions
fixed publicly
details
- Finding IDs
- F-AWS-XRAY-DAEMON-GHA-002
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Pin GitHub Action references to commit SHAs
fixed publicly
details
- Finding IDs
- F-AWS-XRAY-DAEMON-GHA-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
chore: Updating action dependencies to pin to commit sha
fixed publicly
details
- Finding IDs
- F-EKSPIA-GHA-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
chore: Pinning aws-actions/configure-aws-credentials to commit sha
fixed publicly
details
- Finding IDs
- F-EKSPIA-GHA-002
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Pin GitHub Actions to commit SHAs
fixed publicly
details
- Finding IDs
- F-AWS-CW-AGENT-GHA-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
ci: remove latest from toolchain
fixed publicly
details
- Finding IDs
- F-KARPENTER-TOOLCHAIN-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fast-fail on incorrect MaxSpanID
fixed publicly
details
- Finding IDs
- F-SOCI-OOB-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Update standard FS impl to write files with `0o600` permissions
fixed publicly
details
- Finding IDs
- F-AWSRUST-CACHE-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
PST fail-closed + protobuf compatibility fix
fixed publicly
details
- Finding IDs
- F-CEDAR-PST-ERRORCONSTRAINT-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix RCE for canary exploit
Fixed in: public source commit; a separate fixed release is not established
fixed on main (release not confirmed)
details
- Finding IDs
- F-PURPLELLAMA-003
- Status
- fixed on main (release not confirmed)
- Fixed in
- public source commit; a separate fixed release is not established
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(permissions): check deny rules against resolved IPs to prevent numeric hostname bypass
fixed publicly in v2.7.12; Node compat follow-up in v2.8.0
details
- Finding IDs
- F-DENO-001-001
- Status
- fixed publicly in v2.7.12; Node compat follow-up in v2.8.0
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Ignore expireTimerVersion=0 messages
Fixed in: v8.5.0
fixed publicly
details
- Finding IDs
- F-SIGNAL-DESKTOP-EXPIRE-001
- Status
- fixed publicly
- Fixed in
- v8.5.0
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix 'use-after-free' or 'double-free' issues
fixed publicly
details
- Finding IDs
- F-LEDGER-ETH-GCS-CLEANUP-DOUBLEFREE-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fixed dead condition in EIP-712 calldata filtering code
fixed publicly
details
- Finding IDs
- F-LEDGER-ETH-EIP712-CALLDATA-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fixed path traversal in bulk file download via filename sanitization.
fixed publicly
details
- Finding IDs
- F-TELEGRAM-DESKTOP-FILENAME-TRAVERSAL-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly
details
- Finding IDs
- F-TGAND-SECRETCHAT-VECTOR-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly (mapped by code area)
details
- Finding IDs
- F-TGAND-GIFVIDEO-OOB-001 / F-TGAND-GIFVIDEO-001
- Status
- fixed publicly (mapped by code area)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
More strict checks in ffmpeg decodiing.
fixed publicly
details
- Finding IDs
- F-TELEGRAM-DESKTOP-FFMPEG-LINESIZE-MEMCPY-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Upgrade TDLib to tdlib/td@8fc2344
fixed publicly
details
- Finding IDs
- F-TGX-PATHTRAVERSAL-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly
details
- Finding IDs
- F-TELEGRAM-IOS-SSRF-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly
details
- Finding IDs
- F-TELEGRAM-IOS-FFMPEG-LINESIZE-MEMCPY-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly
details
- Finding IDs
- F-TELEGRAM-IOS-FFMPEG-PREVIEW-PIXFMT-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
TelegramApi: regenerate Api*/SecretApiLayer*.swift with safe flag unwrap
fixed publicly
details
- Finding IDs
- F-TELEGRAM-IOS-SECRETAPI-LOCKOUT-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly (mapped by code area)
details
- Finding IDs
- F-TELEGRAM-IOS-TGLINK-001
- Status
- fixed publicly (mapped by code area)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
feat: SCTP signaling improvements for reliable connection establishment
fixed publicly (upstream tgcalls)
details
- Finding IDs
- F-TELEGRAM-IOS-TGCALLS-SIGNALING-001
- Status
- fixed publicly (upstream tgcalls)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
More strict checks in ffmpeg decodiing.
fixed publicly
details
- Finding IDs
- F-TELEGRAM-INTOVF-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
More strict checks in ffmpeg decodiing.
fixed publicly
details
- Finding IDs
- F-TELEGRAM-DESKTOP-FFMPEG-FRAMEAREA-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
restrict tg://iv decode to safe links
fixed publicly
details
- Finding IDs
- F-TELEGRAM-WEBK-TGIV-DECODE-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Harden interaction app<->shell<->webapp.
likely fixed publicly (mapped by hardening area)
details
- Finding IDs
- F-TGDESKTOP-WEBVIEW-004
- Status
- likely fixed publicly (mapped by hardening area)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
General: Better validation for iframe event origins (#6856)
partially likely fixed publicly (re-test needed)
details
- Finding IDs
- F-WEBA-POSTMSG-001
- Status
- partially likely fixed publicly (re-test needed)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
attest: fix uint32 underflow in parseEfiSignatureList
fixed publicly
details
- Finding IDs
- F-GO-ATTESTATION-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix a potential buffer overflow in the animated PNG decoder when parsing malformed fdAT chunks
fixed publicly
details
- Finding IDs
- F-FLUTTER-APNG-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
upb: add bounds check to LocalizeRadix()
fixed publicly
details
- Finding IDs
- F-PROTOBUF-UPB-STRTOF-LOCALE-OVERFLOW-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
bare LF accepted in chunked transfer encoding
fixed publicly
details
- Finding IDs
- F-NGINX-HTTP-REQ-002
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
feat: make scheme configurable with default set to https
fixed publicly
details
- Finding IDs
- F-APISIX-CLS-HTTP-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
chore: set default value of ssl_verify to true
fixed publicly
details
- Finding IDs
- F-APISIX-OIDC-TLS-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(flag): validate template file extension
fixed publicly
details
- Finding IDs
- F-TRIVY-CONFIG-TEMPLATE-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Validate tcg-kp-AIKCertificate EKU
fixed publicly
details
- Finding IDs
- F-SMALLSTEP-AK-EKU-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly
details
- Finding IDs
- F-SMALLSTEP-WEBHOOK-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
jni: Avoid forming &mut when destroying a bridged handle
fixed publicly
details
- Finding IDs
- F-LIBSIGNAL-JNI-DESTROY-UB-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
tool:gpgtar: Check the output directory with --directory.
fixed publicly
details
- Finding IDs
- F-GNUPG-001-002
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
add size limit handler to limit req/resp size (#4310) (#4313)
fixed publicly
details
- Finding IDs
- F-CONFLUENTIC-SCHEMA-REGISTRY-REST-BODY-NOCAP-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Security Bulletin: NVIDIA TensorRT-LLM - May 2026
fixed publicly (mapped to unsafe deserialization class)
details
- Finding IDs
- F-TRTLLM-DESER-001
- Status
- fixed publicly (mapped to unsafe deserialization class)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
chore: deploy Polygon_SpokePool
fixed and deployed publicly
details
- Finding IDs
- F-ACROSS-009-001
- Status
- fixed and deployed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
pkg/authz: Reject requests exceeding body size limit
fixed publicly
details
- Finding IDs
- F-MOBY-001-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
rpcserver: Ensure limited user is always limited
Fixed in: dcrd v2.1.4 (release-v2.1.4)
fixed publicly
details
- Finding IDs
- F-DECRED-DCRD-RPC-LIMITED-ONLY-001
- Status
- fixed publicly
- Fixed in
- dcrd v2.1.4 (release-v2.1.4)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
jsonrpc: Fix bugs in authenticate RPC.
fixed publicly
details
- Finding IDs
- F-DCRWALLET-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
sanitize iframe bodyClasses and bodyStyles in getIframeHtml
fixed in public source; rollout not reverified
details
- Finding IDs
- F-PROTON-WEBCL-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(passkeys): validate caller origin before signing WebAuthn assertions
fixed publicly in 1.40.0 (F-Droid 1.39.2 still behind)
details
- Finding IDs
- F-PROTON-ANDROID-PASS-PASSKEY-ORIGIN-001
- Status
- fixed publicly in 1.40.0 (F-Droid 1.39.2 still behind)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
normalize trailing-dot DNS names before name-constraint matching
Fixed in: Java 1.85 and C# 2.7.0
fixed publicly
details
- Finding IDs
- F-BC-NC-TRAILINGDOT-001
- Status
- fixed publicly
- Fixed in
- Java 1.85 and C# 2.7.0
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fixed publicly
details
- Finding IDs
- F-HUGGINGFACE-003
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
crypto/x509: Fix interaction of DNS exclude constraints with wildcard DNS names.
fixed publicly
details
- Finding IDs
- F-BORINGSSL-001-005
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
crypto/x509: Tighten URI name constraints parsing and matching
fixed publicly
details
- Finding IDs
- F-BORINGSSL-001-004
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
chore(core): improve handling of large messages
fixed publicly
details
- Finding IDs
- F-TREZOR-THP-DOS-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
feat(suite-desktop-core): add check for path traversal
fixed publicly
details
- Finding IDs
- F-TREZOR-SUITE-PT-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(core): use verifiers for translations syscalls
merged
details
- Finding IDs
- F-TREZOR-SYSCALL-TRANSLATIONS-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(core): fix jpegdec syscall verifier
merged
details
- Finding IDs
- F-TREZOR-008
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(crypto): add missing memzero to `ed25519.c`
merged
details
- Finding IDs
- F-TREZOR-CRYPTO-MEMZERO-002
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(crypto): add missing memzero to `cardano.c`
merged
details
- Finding IDs
- F-TREZOR-CRYPTO-MEMZERO-005
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(crypto): add missing memzero to `ecdsa.c`
merged
details
- Finding IDs
- F-TREZOR-CRYPTO-MEMZERO-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(crypto): add missing memzero to `bip32.c`
merged
details
- Finding IDs
- F-TREZOR-CRYPTO-MEMZERO-006
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(rust/trezor-thp): check `payload_len` is not less than `CHECKSUM_LEN`
merged
details
- Finding IDs
- F-TREZOR-THP-FRAGMENT-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(core): fix dma2d syscall verifiers
merged
details
- Finding IDs
- F-TREZOR-009
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(core): fix syscall set filter verifier
merged
details
- Finding IDs
- F-TREZOR-011
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
refactor: stellar confirmations
merged
details
- Finding IDs
- F-TREZOR-004
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(core): fix bug in multisig verification.
merged
details
- Finding IDs
- F-TREZOR-FW-007-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(crypto): Avoid caching uncacheable nodes in bip32.c
merged
details
- Finding IDs
- F-TREZOR-BIP32-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(crypto): clean up stack in hdnode_deserialize()
merged
details
- Finding IDs
- F-TREZOR-CRYPTO-MEMZERO-003
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
feat(connect-webextension): now uses externally_connectable api
merged
details
- Finding IDs
- F-TREZOR-SUITE-PM-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
feat: enhance OAuth handling with zod validation and update response structure
merged
details
- Finding IDs
- F-TREZOR-SUITE-OAUTH-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
enhancement: reject oversized websocket messages
merged
details
- Finding IDs
- F-TREZOR-BLOCKBOOK-WS-READLIMIT-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
enhancement: limit /api/sendtx body size
merged
details
- Finding IDs
- F-TREZOR-BLOCKBOOK-API-SENDTX-READALL-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix: add validation for negative ranges
merged
details
- Finding IDs
- F-TREZOR-BLOCKBOOK-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
enhancement: avoid template.JSStr
merged
details
- Finding IDs
- F-TREZOR-BLOCKBOOK-NFT-URI-XSS-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Use env variable to read user input when mounting FSx volumes
merged
details
- Finding IDs
- F-ECS-FSX-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
pinning github action dependencies to commit sha
merged
details
- Finding IDs
- F-AWS-EKS-PIWEBHOOK-GHA-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
containment-check for targets_base_url in fetch_target
fixed publicly
details
- Finding IDs
- F-AWS-TOUGH-006
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
compound delegation chain decomposed across CVE-2026-6966 and CVE-2026-6967
fixed publicly
details
- Finding IDs
- F-AWS-TOUGH-DELEGATION-CHAIN-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Handle id-pkix-ocsp-nocheck in OCSP responder verification
fixed/documented publicly
details
- Finding IDs
- F-AWSLC-OCSP-RESPONDER-REVOC-0
- Status
- fixed/documented publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix SM2 signature forgery via missing t == 0 rejection in ippsGFpECVerifySM2
fixed publicly
details
- Finding IDs
- F-INTEL-IPP-CRYPTO-SM2-VERIFY-T0-FORGERY-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(qcnl): fix integer overflow in write_callback() on Linux
fixed publicly
details
- Finding IDs
- F-INTEL-SGX-DCAP-QCNL-OVERFLOW-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
lib: [aes-cbc] fix zero-length message handling in decrypt direction
fixed publicly
details
- Finding IDs
- F-INTEL-IPSEC-MB-AES-CBC-LEN0-OOB-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
download-artifact v8: content-type gated artifact decompression
fixed publicly (no GHSA/CVE)
details
- Finding IDs
- F-GHA-ARTNAME-001
- Status
- fixed publicly (no GHSA/CVE)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Bug fixes ported from 2026.1
fixed publicly (functional bug, no CVE)
details
- Finding IDs
- F-AMD-BOOTGEN-003
- Status
- fixed publicly (functional bug, no CVE)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
arm RLDP receiver timeouts and validate FEC before receiver allocation
fixed in public source; rollout not reverified
details
- Finding IDs
- F-TON-006-001
- Status
- fixed in public source; rollout not reverified
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
node/security-relevant fixes
fixed publicly (mapped by date and fix area)
details
- Finding IDs
- F-TON-009-001
- Status
- fixed publicly (mapped by date and fix area)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Fix empty collated data / Removing null-consensus
fixed publicly (mapped by date and fix area)
details
- Finding IDs
- F-TON-010-001
- Status
- fixed publicly (mapped by date and fix area)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix SAN dNSName constraints matching
fixed publicly (GHSA metadata unconfirmed)
details
- Finding IDs
- F-LIBRESSL-NC-WILDCARD-001
- Status
- fixed publicly (GHSA metadata unconfirmed)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
mark ApkUpdatePackageInstallerReceiver non-exported
fixed publicly (high confidence mapping)
details
- Finding IDs
- F-SIGANDROID-INTENT-001
- Status
- fixed publicly (high confidence mapping)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
validate pre-key key-id ranges
likely fixed publicly (conditional mapping)
details
- Finding IDs
- F-SIGNAL-SERVER-PREKEY-001
- Status
- likely fixed publicly (conditional mapping)
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
uhv: use-after-free read in sanitizeHeadersWithUnderscores with duplicate underscore headers
fixed publicly via issue closure
details
- Finding IDs
- F-ENVOY-001-003
- Status
- fixed publicly via issue closure
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix(wallet-api): add domain validation for customDappUrl
fixed publicly
details
- Finding IDs
- F-LEDGER-LIVE-DESKTOP-CUSTOMDAPPURL-001
- Status
- fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Avoid content key packet verification fallback on publicly shared nodes
likely fixed publicly
details
- Finding IDs
- F-PROTON-DRIVE-SDK-001
- Status
- likely fixed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
verifyImages(required): enforce matching images after non-matching images
fixed in Kyverno v1.18.2 and v1.19.0
details
- Finding IDs
- F-NOTARYPROJECT-KYVERNO-001
- Status
- fixed in Kyverno v1.18.2 and v1.19.0
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
sandbox Terraform filesystem functions
fixed in Trivy v0.71.0+
details
- Finding IDs
- F-TRIVY-TF-FILE-001
- Status
- fixed in Trivy v0.71.0+
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
ScanQrModal: fix domain check for cashlinks
fixed publicly in wallet v3.2.3
details
- Finding IDs
- F-NIMIQ-SCANQR-JSREDIRECT-001
- Status
- fixed publicly in wallet v3.2.3
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix: webhook initialization order
merged
details
- Finding IDs
- F-ESO-LABELBYPASS-001
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Updated to use the latest plugin SDK
fixed before reportnot counted
details
- Finding IDs
- F-LEDGER-YEARN-RECIPIENT-HIDDEN-001
- Status
- fixed before report
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Farewell 'Device Bridge' in LLD (#2635)
feature removed publiclynot counted
details
- Finding IDs
- F-LEDGER-LIVE-WSBRIDGE-001
- Status
- feature removed publicly
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
Track interactions in webview for clipboard access
fixed before reportnot counted
details
- Finding IDs
- F-TGDESKTOP-CLIPBOARD-001
- Status
- fixed before report
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
TDLib public change; vector-overflow fix mapping unconfirmed
fix mapping unconfirmednot counted
details
- Finding IDs
- F-TELEGRAM-VECOVF-001
- Status
- fix mapping unconfirmed
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix: register defers immediately in scan.go
merged
details
- Finding IDs
- F-MALCONTENT-006
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix treewide: register more defers immediately
merged
details
- Finding IDs
- F-MALCONTENT-008
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
fix: abstract out cpio operations to helper function
merged
details
- Finding IDs
- F-MALCONTENT-007
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
asn1parse: add small ber/der edge-case seeds
applied upstream
details
- Finding IDs
- F-OPENSSL-ASN1-001
- Status
- applied upstream
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
test: add ECDSA activation regression coverage
merged
details
- Finding IDs
- F-GO-ATTESTATION-004
- Status
- merged
Full sources, classification reasons and claim limits are on the finding page.
—score not recorded
signing-path integrity gate bypass via merkle preimage binding break
Fixed in: commit 0586ab2
patchednot counted
details
- Finding IDs
- F-LEDGER-BTC-MERKLE-001
- Status
- patched
- Fixed in
- commit 0586ab2
Full sources, classification reasons and claim limits are on the finding page.