Vulnerabilities
Vulnerable Software
Security Vulnerabilities
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVSS Score
6.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVSS Score
6.5
EPSS Score
0.007
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVSS Score
8.1
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVSS Score
6.6
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
CVSS Score
7.1
EPSS Score
0.003
Published
2026-10-01
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-09-30
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-30
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-30
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-30
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-30


Contact Us

Shodan ® - All rights reserved