GitLab Patch: Fixes CI/CD Credential Theft & Unauthenticated DoS Attacks
GitLab Patch: Fixes CI/CD Credential Theft & Unauthenticated DoS Attacks GitLab has released an important security update today affecting both its Community Edition (CE) and Enterprise Edition (EE). The release addresses multiple high-severity vulnerabilities, ranging from … Read more Published Date: Nov 26, 2025 (1 hour, 33 minutes ago) Vulnerabilities has been mentioned in this article.
CVE-2025-66035 – Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site […]
CVE-2025-66030 – node-forge ASN.1 OID Integer Truncation
The following table lists the changes that have been made to the CVE-2025-66030 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]
CVE-2025-66031 – node-forge ASN.1 Unbounded Recursion
The following table lists the changes that have been made to the CVE-2025-66031 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]
CVE-2025-64344 – Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. […]
CVE-2025-64335 – Suricata is vulnerable to a null deref when used with base64_data
The following table lists the changes that have been made to the CVE-2025-64335 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]
CVE-2025-64334 – Suricata is vulnerable to unbounded memory growth for decompression
The following table lists the changes that have been made to the CVE-2025-64334 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]
CVE-2025-64333 – Suricata is vulnerable to a stack overflow from big content-type
The following table lists the changes that have been made to the CVE-2025-64333 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]
CVE-2025-64332 – Suricata is vulnerable to a stack overflow on larger compressed data
The following table lists the changes that have been made to the CVE-2025-64332 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]
CVE-2025-64331 – Suricata is vulnerable to a stack overflow on large file transfers with http-body-printable
The following table lists the changes that have been made to the CVE-2025-64331 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 26, 2025 Action […]