kb: expand authorized lab coverage and intel automation

这个提交包含在:
hao
2026-03-16 22:04:51 -07:00
父节点 cda31e86c7
当前提交 d0120fbf10
修改 592 个文件,包含 29025 行新增267 行删除

查看文件

@@ -0,0 +1,36 @@
# frameworks
> 自动生成系统分组索引
- 系统数量: `29`
- 允许范围: `lab-local`, `lab-public`, `authorized-third-party`
- [Angular](/Users/x/websafe/07-framework-security/frameworks/angular/README.md)
- [ASP.NET Core](/Users/x/websafe/07-framework-security/frameworks/aspnet-core/README.md)
- [Astro](/Users/x/websafe/07-framework-security/frameworks/astro/README.md)
- [Django](/Users/x/websafe/07-framework-security/frameworks/django/README.md)
- [Echo](/Users/x/websafe/07-framework-security/frameworks/echo/README.md)
- [esbuild](/Users/x/websafe/07-framework-security/frameworks/esbuild/README.md)
- [Express](/Users/x/websafe/07-framework-security/frameworks/express/README.md)
- [Fastify](/Users/x/websafe/07-framework-security/frameworks/fastify/README.md)
- [Flask](/Users/x/websafe/07-framework-security/frameworks/flask/README.md)
- [Gin](/Users/x/websafe/07-framework-security/frameworks/gin/README.md)
- [Hapi](/Users/x/websafe/07-framework-security/frameworks/hapi/README.md)
- [Koa](/Users/x/websafe/07-framework-security/frameworks/koa/README.md)
- [Laravel](/Users/x/websafe/07-framework-security/frameworks/laravel/README.md)
- [NestJS](/Users/x/websafe/07-framework-security/frameworks/nestjs/README.md)
- [Next.js](/Users/x/websafe/07-framework-security/frameworks/nextjs/README.md)
- [Node.js](/Users/x/websafe/07-framework-security/frameworks/nodejs/README.md)
- [Nuxt](/Users/x/websafe/07-framework-security/frameworks/nuxt/README.md)
- [React](/Users/x/websafe/07-framework-security/frameworks/react/README.md)
- [Ruby on Rails](/Users/x/websafe/07-framework-security/frameworks/rails/README.md)
- [Spring Boot](/Users/x/websafe/07-framework-security/frameworks/spring-boot/README.md)
- [Spring Framework](/Users/x/websafe/07-framework-security/frameworks/spring-framework/README.md)
- [Spring Security](/Users/x/websafe/07-framework-security/frameworks/spring-security/README.md)
- [SvelteKit](/Users/x/websafe/07-framework-security/frameworks/sveltekit/README.md)
- [Symfony](/Users/x/websafe/07-framework-security/frameworks/symfony/README.md)
- [Undici](/Users/x/websafe/07-framework-security/frameworks/undici/README.md)
- [Vite](/Users/x/websafe/07-framework-security/frameworks/vite/README.md)
- [Vue](/Users/x/websafe/07-framework-security/frameworks/vue/README.md)
- [webpack](/Users/x/websafe/07-framework-security/frameworks/webpack/README.md)
- [Werkzeug](/Users/x/websafe/07-framework-security/frameworks/werkzeug/README.md)

查看文件

@@ -0,0 +1,30 @@
# Angular
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `angular`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Angular](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Angular
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/angular`
- 修复主题: xss-output-encoding, template-injection-guard, csp-trusted-types
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/angular/INDEX.md)
- Registry 统计: [angular.json](/Users/x/websafe/08-threat-intel/registry/systems/angular.json)

查看文件

@@ -0,0 +1,29 @@
# ASP.NET Core
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `aspnet-core`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [NVD ASP.NET Core](https://nvd.nist.gov/vuln/search) (keyword=ASP.NET Core; mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# ASP.NET Core
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/aspnet-core`
- 修复主题: authz-server-side-recheck, xss-output-encoding, file-upload-validation
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/aspnet-core/INDEX.md)
- Registry 统计: [aspnet-core.json](/Users/x/websafe/08-threat-intel/registry/systems/aspnet-core.json)

查看文件

@@ -0,0 +1,30 @@
# Astro
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `astro`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Astro](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Astro
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/astro`
- 修复主题: authz-server-side-recheck, csp-trusted-types
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/astro/INDEX.md)
- Registry 统计: [astro.json](/Users/x/websafe/08-threat-intel/registry/systems/astro.json)

查看文件

@@ -0,0 +1,30 @@
# Django
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `django`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Django Security RSS](https://www.djangoproject.com/weblog/feeds/tags/security/) (mode=core)
- `official` [OSV Django](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Django
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/django`
- 修复主题: xss-output-encoding, path-traversal-guard, file-upload-validation
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/django/INDEX.md)
- Registry 统计: [django.json](/Users/x/websafe/08-threat-intel/registry/systems/django.json)

查看文件

@@ -0,0 +1,29 @@
# Echo
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `echo`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [OSV Echo](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Echo
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/echo`
- 修复主题: proxy-trust-boundary, token-cookie-storage
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/echo/INDEX.md)
- Registry 统计: [echo.json](/Users/x/websafe/08-threat-intel/registry/systems/echo.json)

查看文件

@@ -0,0 +1,30 @@
# esbuild
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `esbuild`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV esbuild](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# esbuild
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/esbuild`
- 修复主题: dependency-upgrade-policy, file-upload-validation
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/esbuild/INDEX.md)
- Registry 统计: [esbuild.json](/Users/x/websafe/08-threat-intel/registry/systems/esbuild.json)

查看文件

@@ -0,0 +1,30 @@
# Express
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `express`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Express](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Express
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/express`
- 修复主题: xss-output-encoding, ssrf-url-validation, proxy-trust-boundary
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/express/INDEX.md)
- Registry 统计: [express.json](/Users/x/websafe/08-threat-intel/registry/systems/express.json)

查看文件

@@ -0,0 +1,30 @@
# Fastify
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `fastify`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Fastify](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Fastify
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/fastify`
- 修复主题: proxy-trust-boundary, ssrf-url-validation, xss-output-encoding
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/fastify/INDEX.md)
- Registry 统计: [fastify.json](/Users/x/websafe/08-threat-intel/registry/systems/fastify.json)

查看文件

@@ -0,0 +1,30 @@
# Flask
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `flask`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [OSV Flask](https://osv.dev/) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=pip; mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Flask
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/flask`
- 修复主题: xss-output-encoding, ssrf-url-validation, token-cookie-storage
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/flask/INDEX.md)
- Registry 统计: [flask.json](/Users/x/websafe/08-threat-intel/registry/systems/flask.json)

查看文件

@@ -0,0 +1,29 @@
# Gin
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `gin`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [OSV Gin](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Gin
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/gin`
- 修复主题: proxy-trust-boundary, xss-output-encoding
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/gin/INDEX.md)
- Registry 统计: [gin.json](/Users/x/websafe/08-threat-intel/registry/systems/gin.json)

查看文件

@@ -0,0 +1,30 @@
# Hapi
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `hapi`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Hapi](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Hapi
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/hapi`
- 修复主题: proxy-trust-boundary, token-cookie-storage
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/hapi/INDEX.md)
- Registry 统计: [hapi.json](/Users/x/websafe/08-threat-intel/registry/systems/hapi.json)

查看文件

@@ -0,0 +1,30 @@
# Koa
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `koa`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Koa](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Koa
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/koa`
- 修复主题: proxy-trust-boundary, ssrf-url-validation
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/koa/INDEX.md)
- Registry 统计: [koa.json](/Users/x/websafe/08-threat-intel/registry/systems/koa.json)

查看文件

@@ -0,0 +1,30 @@
# Laravel
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `laravel`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=composer; mode=core)
- `official` [OSV Laravel](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Laravel
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/laravel`
- 修复主题: xss-output-encoding, authz-server-side-recheck, file-upload-validation
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/laravel/INDEX.md)
- Registry 统计: [laravel.json](/Users/x/websafe/08-threat-intel/registry/systems/laravel.json)

查看文件

@@ -0,0 +1,30 @@
# NestJS
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `nestjs`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV NestJS](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# NestJS
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/nestjs`
- 修复主题: authz-server-side-recheck, token-cookie-storage, ssrf-url-validation
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/nestjs/INDEX.md)
- Registry 统计: [nestjs.json](/Users/x/websafe/08-threat-intel/registry/systems/nestjs.json)

查看文件

@@ -0,0 +1,56 @@
# Next.js
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `nextjs`
- 分类: `frameworks`
- 覆盖策略: `history-full`
- 总案例数: `26`
- 近 30 天新增/更新: `5`
- 重点 Markdown 案例数: `26`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Next.js Advisories](https://github.com/vercel/next.js/security/advisories) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Next.js](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components | `low` | `generated` | `official` | `2026-02-13T00:43:52.836085Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-ghsa-h25m-26qc-wcjf.md) |
| Next.js has Unbounded Memory Consumption via PPR Resume Endpoint | `low` | `generated` | `official` | `2026-02-06T13:13:43.709252Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-59472.md) |
| Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration | `low` | `generated` | `official` | `2026-02-10T01:28:46.973023Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-59471.md) |
| Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up | `low` | `generated` | `official` | `2026-02-04T02:46:38.768104Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-ghsa-5j59-xgg2-r9c4.md) |
| Next Server Actions Source Code Exposure | `low` | `generated` | `official` | `2026-02-04T02:51:40.627151Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-ghsa-w37m-7fhw-fmv9.md) |
| Next Vulnerable to Denial of Service with Server Components | `low` | `generated` | `official` | `2026-02-04T03:55:54.855562Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-ghsa-mwv6-3258-q52c.md) |
| Next.js is vulnerable to RCE in React flight protocol | `low` | `generated` | `official` | `2026-02-04T03:45:15.823345Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-ghsa-9qr9-h5gf-34mp.md) |
| Next.js Affected by Cache Key Confusion for Image Optimization API Routes | `low` | `generated` | `official` | `2026-02-04T02:50:08.291668Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-57752.md) |
| Next.js Content Injection Vulnerability for Image Optimization | `low` | `generated` | `official` | `2026-02-04T04:35:34.538107Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-55173.md) |
| Next.js Improper Middleware Redirect Handling Leads to SSRF | `low` | `generated` | `official` | `2026-02-04T04:20:45.658010Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-57822.md) |
| Next.JS vulnerability can lead to DoS via cache poisoning | `low` | `generated` | `official` | `2025-07-03T21:49:52Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-49826.md) |
| Next.js has a Cache poisoning vulnerability due to omission of the Vary header | `low` | `generated` | `official` | `2026-02-04T02:37:18.974477Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-49005.md) |
| Information exposure in Next.js dev server due to lack of origin verification | `medium` | `generated` | `official` | `2025-06-13T14:41:21Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-48068.md) |
| Next.js Race Condition to Cache Poisoning | `low` | `generated` | `official` | `2025-09-26T17:48:29Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-32421.md) |
| Next.js may leak x-middleware-subrequest-id to external hosts | `medium` | `generated` | `official` | `2025-10-13T15:35:50Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-30218.md) |
| Authorization Bypass in Next.js Middleware | `low` | `generated` | `official` | `2026-03-04T15:06:29.993197Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2025-29927.md) |
| Next.js Allows a Denial of Service (DoS) with Server Actions | `low` | `generated` | `official` | `2026-02-04T04:36:04.252972Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2024-56332.md) |
| Next.js authorization bypass vulnerability | `low` | `generated` | `official` | `2025-09-10T21:12:24Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2024-51479.md) |
| Denial of Service condition in Next.js image optimization | `low` | `generated` | `official` | `2026-02-04T03:25:43.295558Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2024-47831.md) |
| Next.js Cache Poisoning | `low` | `generated` | `official` | `2026-02-04T03:45:33.402195Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2024-46982.md) |
| Next.js Server-Side Request Forgery in Server Actions | `low` | `generated` | `official` | `2026-02-04T03:32:36.434669Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2024-34351.md) |
| Unexpected server crash in Next.js. | `low` | `generated` | `official` | `2026-03-13T22:00:36.554552Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2021-43803.md) |
| XSS in Image Optimization API for Next.js | `low` | `generated` | `official` | `2026-03-13T22:00:20.154452Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2021-39178.md) |
| Open Redirect in Next.js | `low` | `generated` | `official` | `2026-03-13T22:00:08.038285Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2021-37699.md) |
| Open Redirect in Next.js versions | `low` | `generated` | `official` | `2026-03-13T22:14:13.665535Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2020-15242.md) |
| Directory Traversal in Next.js | `low` | `generated` | `official` | `2025-09-26T17:49:56Z` | [link](/Users/x/websafe/07-framework-security/frameworks/nextjs/cases/nextjs-cve-2020-5284.md) |

查看文件

@@ -0,0 +1,16 @@
# Next.js
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `history-full`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/nextjs`
- 修复主题: authz-server-side-recheck, proxy-trust-boundary, token-cookie-storage
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/nextjs/INDEX.md)
- Registry 统计: [nextjs.json](/Users/x/websafe/08-threat-intel/registry/systems/nextjs.json)

查看文件

@@ -0,0 +1,83 @@
---
title: "Open Redirect in Next.js versions"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2020-10-08T19:28:07Z"
updated_date: "2026-03-13T22:14:13.665535Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2020-15242"
- "GHSA-x56p-c8cg-q435"
affected_versions:
- "introduced=9.5.0, fixed<9.5.4"
fixed_versions:
- "9.5.4"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-x56p-c8cg-q435"
---
# Open Redirect in Next.js versions
## 事件层
- Canonical ID: `nextjs--CVE-2020-15242`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-x56p-c8cg-q435
- 影响版本: `introduced=9.5.0, fixed<9.5.4`
- 修复版本: `9.5.4`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2020-15242
- https://github.com/vercel/next.js
- https://github.com/zeit/next.js/releases/tag/v9.5.4
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,92 @@
---
title: "Directory Traversal in Next.js"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2020-03-30T20:40:50Z"
updated_date: "2025-09-26T17:49:56Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2020-5284"
- "GHSA-fq77-7p7r-83rj"
affected_versions:
- "introduced=0.9.9, fixed<9.3.2"
fixed_versions:
- "9.3.2"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "path-traversal-guard"
primary_source: "https://github.com/zeit/next.js/security/advisories/GHSA-fq77-7p7r-83rj"
---
# Directory Traversal in Next.js
## 事件层
- Canonical ID: `nextjs--CVE-2020-5284`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/zeit/next.js/security/advisories/GHSA-fq77-7p7r-83rj
- 影响版本: `introduced=0.9.9, fixed<9.3.2`
- 修复版本: `9.3.2`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2020-5284
- https://github.com/zeit/next.js/releases/tag/v9.3.2
- https://www.npmjs.com/advisories/1503
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/javascript-typescript/path-traversal-guard.md)
- [nodejs:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/nodejs/path-traversal-guard.md)
- [java:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/java/path-traversal-guard.md)
- [php:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/php/path-traversal-guard.md)
- [python:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/python/path-traversal-guard.md)
- [ruby:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/ruby/path-traversal-guard.md)
- [csharp:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/csharp/path-traversal-guard.md)
- [go:path-traversal-guard](/Users/x/websafe/05-defense/secure-code/go/path-traversal-guard.md)

查看文件

@@ -0,0 +1,92 @@
---
title: "Open Redirect in Next.js"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2021-08-12T14:51:14Z"
updated_date: "2026-03-13T22:00:08.038285Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2021-37699"
- "GHSA-vxf5-wxwp-m7g9"
affected_versions:
- "introduced=0.9.9, fixed<11.1.0"
fixed_versions:
- "11.1.0"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-vxf5-wxwp-m7g9"
---
# Open Redirect in Next.js
## 事件层
- Canonical ID: `nextjs--CVE-2021-37699`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-vxf5-wxwp-m7g9
- 影响版本: `introduced=0.9.9, fixed<11.1.0`
- 修复版本: `11.1.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2021-37699
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v11.1.0
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)

查看文件

@@ -0,0 +1,94 @@
---
title: "XSS in Image Optimization API for Next.js"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2021-09-01T18:24:22Z"
updated_date: "2026-03-13T22:00:20.154452Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2021-39178"
- "GHSA-9gr3-7897-pp7m"
affected_versions:
- "introduced=10.0.0, fixed<11.1.1"
fixed_versions:
- "11.1.1"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "xss-output-encoding"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-9gr3-7897-pp7m"
---
# XSS in Image Optimization API for Next.js
## 事件层
- Canonical ID: `nextjs--CVE-2021-39178`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-9gr3-7897-pp7m
- 影响版本: `introduced=10.0.0, fixed<11.1.1`
- 修复版本: `11.1.1`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2021-39178
- https://github.com/vercel/next.js/pull/28620
- https://github.com/vercel/next.js/commit/7afc97c5744b38bdf36aa7f87625f438224688aa
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v11.1.1
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/javascript-typescript/xss-output-encoding.md)
- [nodejs:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/nodejs/xss-output-encoding.md)
- [java:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/java/xss-output-encoding.md)
- [php:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/php/xss-output-encoding.md)
- [python:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/python/xss-output-encoding.md)
- [ruby:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/ruby/xss-output-encoding.md)
- [csharp:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/csharp/xss-output-encoding.md)
- [go:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/go/xss-output-encoding.md)

查看文件

@@ -0,0 +1,97 @@
---
title: "Unexpected server crash in Next.js."
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2021-12-07T21:12:09Z"
updated_date: "2026-03-13T22:00:36.554552Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2021-43803"
- "GHSA-25mp-g6fv-mqxx"
affected_versions:
- "introduced=12.0.0, fixed<12.0.5"
- "introduced=0.9.9, fixed<11.1.3"
fixed_versions:
- "12.0.5"
- "11.1.3"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-25mp-g6fv-mqxx"
---
# Unexpected server crash in Next.js.
## 事件层
- Canonical ID: `nextjs--CVE-2021-43803`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-25mp-g6fv-mqxx
- 影响版本: `introduced=12.0.0, fixed<12.0.5, introduced=0.9.9, fixed<11.1.3`
- 修复版本: `12.0.5, 11.1.3`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2021-43803
- https://github.com/vercel/next.js/pull/32080
- https://github.com/vercel/next.js/commit/6d98b4fb4315dec1badecf0e9bdc212a4272b264
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v11.1.3
- https://github.com/vercel/next.js/releases/v12.0.5
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)

查看文件

@@ -0,0 +1,93 @@
---
title: "Next.js Server-Side Request Forgery in Server Actions"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-05-09T21:18:57Z"
updated_date: "2026-02-04T03:32:36.434669Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-34351"
- "GHSA-fr5h-rqp8-mj6g"
affected_versions:
- "introduced=13.4.0, fixed<14.1.1"
fixed_versions:
- "14.1.1"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "ssrf-url-validation"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g"
---
# Next.js Server-Side Request Forgery in Server Actions
## 事件层
- Canonical ID: `nextjs--CVE-2024-34351`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g
- 影响版本: `introduced=13.4.0, fixed<14.1.1`
- 修复版本: `14.1.1`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-34351
- https://github.com/vercel/next.js/pull/62561
- https://github.com/vercel/next.js/commit/8f7a6ca7d21a97bc9f7a1bbe10427b5ad74b9085
- https://github.com/vercel/next.js
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)

查看文件

@@ -0,0 +1,86 @@
---
title: "Next.js Cache Poisoning"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-09-17T21:58:09Z"
updated_date: "2026-02-04T03:45:33.402195Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-46982"
- "GHSA-gp8f-8m3g-qvj9"
affected_versions:
- "introduced=13.5.1, fixed<13.5.7"
- "introduced=14.0.0, fixed<14.2.10"
fixed_versions:
- "13.5.7"
- "14.2.10"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-gp8f-8m3g-qvj9"
---
# Next.js Cache Poisoning
## 事件层
- Canonical ID: `nextjs--CVE-2024-46982`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-gp8f-8m3g-qvj9
- 影响版本: `introduced=13.5.1, fixed<13.5.7, introduced=14.0.0, fixed<14.2.10`
- 修复版本: `13.5.7, 14.2.10`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-46982
- https://github.com/vercel/next.js/commit/7ed7f125e07ef0517a331009ed7e32691ba403d3
- https://github.com/vercel/next.js/commit/bd164d53af259c05f1ab434004bcfdd3837d7cda
- https://github.com/vercel/next.js
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,83 @@
---
title: "Denial of Service condition in Next.js image optimization"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-10-14T19:45:21Z"
updated_date: "2026-02-04T03:25:43.295558Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-47831"
- "GHSA-g77x-44xx-532m"
affected_versions:
- "introduced=10.0.0, fixed<14.2.7"
fixed_versions:
- "14.2.7"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-g77x-44xx-532m"
---
# Denial of Service condition in Next.js image optimization
## 事件层
- Canonical ID: `nextjs--CVE-2024-47831`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-g77x-44xx-532m
- 影响版本: `introduced=10.0.0, fixed<14.2.7`
- 修复版本: `14.2.7`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-47831
- https://github.com/vercel/next.js/commit/d11cbc9ff0b1aaefabcba9afe1e562e0b1fde65a
- https://github.com/vercel/next.js
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,84 @@
---
title: "Next.js authorization bypass vulnerability"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-12-17T15:09:06Z"
updated_date: "2025-09-10T21:12:24Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-51479"
- "GHSA-7gfc-8cq8-jh5f"
affected_versions:
- "introduced=9.5.5, fixed<14.2.15"
fixed_versions:
- "14.2.15"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-7gfc-8cq8-jh5f"
---
# Next.js authorization bypass vulnerability
## 事件层
- Canonical ID: `nextjs--CVE-2024-51479`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-7gfc-8cq8-jh5f
- 影响版本: `introduced=9.5.5, fixed<14.2.15`
- 修复版本: `14.2.15`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-51479
- https://github.com/vercel/next.js/commit/1c8234eb20bc8afd396b89999a00f06b61d72d7b
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v14.2.15
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,86 @@
---
title: "Next.js Allows a Denial of Service (DoS) with Server Actions"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-01-03T20:19:29Z"
updated_date: "2026-02-04T04:36:04.252972Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-56332"
- "GHSA-7m27-7ghc-44w9"
affected_versions:
- "introduced=13.0.0, fixed<13.5.8"
- "introduced=14.0.0, fixed<14.2.21"
- "introduced=15.0.0, fixed<15.1.2"
fixed_versions:
- "13.5.8"
- "14.2.21"
- "15.1.2"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-7m27-7ghc-44w9"
---
# Next.js Allows a Denial of Service (DoS) with Server Actions
## 事件层
- Canonical ID: `nextjs--CVE-2024-56332`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-7m27-7ghc-44w9
- 影响版本: `introduced=13.0.0, fixed<13.5.8, introduced=14.0.0, fixed<14.2.21, introduced=15.0.0, fixed<15.1.2`
- 修复版本: `13.5.8, 14.2.21, 15.1.2`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-56332
- https://github.com/vercel/next.js
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,96 @@
---
title: "Authorization Bypass in Next.js Middleware"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-03-21T15:20:12Z"
updated_date: "2026-03-04T15:06:29.993197Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-29927"
- "GHSA-f82v-jwr5-mffw"
affected_versions:
- "introduced=13.0.0, fixed<13.5.9"
- "introduced=14.0.0, fixed<14.2.25"
- "introduced=15.0.0, fixed<15.2.3"
- "introduced=12.0.0, fixed<12.3.5"
fixed_versions:
- "13.5.9"
- "14.2.25"
- "15.2.3"
- "12.3.5"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw"
---
# Authorization Bypass in Next.js Middleware
## 事件层
- Canonical ID: `nextjs--CVE-2025-29927`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw
- 影响版本: `introduced=13.0.0, fixed<13.5.9, introduced=14.0.0, fixed<14.2.25, introduced=15.0.0, fixed<15.2.3, introduced=12.0.0, fixed<12.3.5`
- 修复版本: `13.5.9, 14.2.25, 15.2.3, 12.3.5`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-29927
- https://github.com/vercel/next.js/commit/52a078da3884efe6501613c7834a3d02a91676d2
- https://github.com/vercel/next.js/commit/5fd3ae8f8542677c6294f32d18022731eab6fe48
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v12.3.5
- https://github.com/vercel/next.js/releases/tag/v13.5.9
- https://security.netapp.com/advisory/ntap-20250328-0002
- https://vercel.com/changelog/vercel-firewall-proactively-protects-against-vulnerability-with-middleware
- http://www.openwall.com/lists/oss-security/2025/03/23/3
- http://www.openwall.com/lists/oss-security/2025/03/23/4
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,93 @@
---
title: "Next.js may leak x-middleware-subrequest-id to external hosts"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-04-02T22:35:37Z"
updated_date: "2025-10-13T15:35:50Z"
severity: "medium"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-30218"
- "GHSA-223j-4rm8-mrmf"
affected_versions:
- "12.3.5"
- "13.5.9"
- "14.2.25"
- "15.2.3"
- "introduced=12.3.5, fixed<12.3.6"
- "introduced=13.5.9, fixed<13.5.10"
- "introduced=14.2.25, fixed<14.2.26"
- "introduced=15.2.3, fixed<15.2.4"
fixed_versions:
- "12.3.6"
- "13.5.10"
- "14.2.26"
- "15.2.4"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-223j-4rm8-mrmf"
---
# Next.js may leak x-middleware-subrequest-id to external hosts
## 事件层
- Canonical ID: `nextjs--CVE-2025-30218`
- 系统: `nextjs`
- 严重度: `medium`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-223j-4rm8-mrmf
- 影响版本: `12.3.5, 13.5.9, 14.2.25, 15.2.3, introduced=12.3.5, fixed<12.3.6, introduced=13.5.9, fixed<13.5.10, introduced=14.2.25, fixed<14.2.26, introduced=15.2.3, fixed<15.2.4`
- 修复版本: `12.3.6, 13.5.10, 14.2.26, 15.2.4`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-30218
- https://github.com/vercel/next.js
- https://vercel.com/changelog/cve-2025-30218-5DREmEH765PoeAsrNNQj3O
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,85 @@
---
title: "Next.js Race Condition to Cache Poisoning"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-05-15T14:12:26Z"
updated_date: "2025-09-26T17:48:29Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-32421"
- "GHSA-qpjv-v59x-3qc4"
affected_versions:
- "introduced=0.9.9, fixed<14.2.24"
- "introduced=15.0.0, fixed<15.1.6"
fixed_versions:
- "14.2.24"
- "15.1.6"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-qpjv-v59x-3qc4"
---
# Next.js Race Condition to Cache Poisoning
## 事件层
- Canonical ID: `nextjs--CVE-2025-32421`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-qpjv-v59x-3qc4
- 影响版本: `introduced=0.9.9, fixed<14.2.24, introduced=15.0.0, fixed<15.1.6`
- 修复版本: `14.2.24, 15.1.6`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-32421
- https://github.com/vercel/next.js
- https://vercel.com/changelog/cve-2025-32421
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,85 @@
---
title: "Information exposure in Next.js dev server due to lack of origin verification"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-05-28T21:52:13Z"
updated_date: "2025-06-13T14:41:21Z"
severity: "medium"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-48068"
- "GHSA-3h52-269p-cp9r"
affected_versions:
- "introduced=15.0.0, fixed<15.2.2"
- "introduced=13.0, fixed<14.2.30"
fixed_versions:
- "15.2.2"
- "14.2.30"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-3h52-269p-cp9r"
---
# Information exposure in Next.js dev server due to lack of origin verification
## 事件层
- Canonical ID: `nextjs--CVE-2025-48068`
- 系统: `nextjs`
- 严重度: `medium`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-3h52-269p-cp9r
- 影响版本: `introduced=15.0.0, fixed<15.2.2, introduced=13.0, fixed<14.2.30`
- 修复版本: `15.2.2, 14.2.30`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-48068
- https://github.com/vercel/next.js
- https://vercel.com/changelog/cve-2025-48068
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,87 @@
---
title: "Next.js has a Cache poisoning vulnerability due to omission of the Vary header"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-07-03T20:30:18Z"
updated_date: "2026-02-04T02:37:18.974477Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-49005"
- "GHSA-r2fc-ccr8-96c4"
affected_versions:
- "introduced=15.3.0, fixed<15.3.3"
fixed_versions:
- "15.3.3"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-r2fc-ccr8-96c4"
---
# Next.js has a Cache poisoning vulnerability due to omission of the Vary header
## 事件层
- Canonical ID: `nextjs--CVE-2025-49005`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-r2fc-ccr8-96c4
- 影响版本: `introduced=15.3.0, fixed<15.3.3`
- 修复版本: `15.3.3`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-49005
- https://github.com/vercel/next.js/issues/79346
- https://github.com/vercel/next.js/pull/79939
- https://github.com/vercel/next.js/commit/ec202eccf05820b60c6126d6411fe16766ecc066
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v15.3.3
- https://vercel.com/changelog/cve-2025-49005
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,86 @@
---
title: "Next.JS vulnerability can lead to DoS via cache poisoning "
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-07-03T21:14:48Z"
updated_date: "2025-07-03T21:49:52Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-49826"
- "GHSA-67rr-84xm-4c7r"
affected_versions:
- "introduced=15.0.4-canary.51, fixed<15.1.8"
fixed_versions:
- "15.1.8"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-67rr-84xm-4c7r"
---
# Next.JS vulnerability can lead to DoS via cache poisoning
## 事件层
- Canonical ID: `nextjs--CVE-2025-49826`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-67rr-84xm-4c7r
- 影响版本: `introduced=15.0.4-canary.51, fixed<15.1.8`
- 修复版本: `15.1.8`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-49826
- https://github.com/vercel/next.js/commit/16bfce64ef2157f2c1dfedcfdb7771bc63103fd2
- https://github.com/vercel/next.js/commit/a15b974ed707d63ad4da5b74c1441f5b7b120e93
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v15.1.8
- https://vercel.com/changelog/cve-2025-49826
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,87 @@
---
title: "Next.js Content Injection Vulnerability for Image Optimization"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-08-29T21:59:55Z"
updated_date: "2026-02-04T04:35:34.538107Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-55173"
- "GHSA-xv57-4mr9-wg8v"
affected_versions:
- "introduced=0.9.9, fixed<14.2.31"
- "introduced=15.0.0, fixed<15.4.5"
fixed_versions:
- "14.2.31"
- "15.4.5"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-xv57-4mr9-wg8v"
---
# Next.js Content Injection Vulnerability for Image Optimization
## 事件层
- Canonical ID: `nextjs--CVE-2025-55173`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-xv57-4mr9-wg8v
- 影响版本: `introduced=0.9.9, fixed<14.2.31, introduced=15.0.0, fixed<15.4.5`
- 修复版本: `14.2.31, 15.4.5`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-55173
- https://github.com/vercel/next.js/commit/6b12c60c61ee80cb0443ccd20de82ca9b4422ddd
- https://github.com/vercel/next.js
- https://vercel.com/changelog/cve-2025-55173
- http://vercel.com/changelog/cve-2025-55173
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,87 @@
---
title: "Next.js Affected by Cache Key Confusion for Image Optimization API Routes"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-08-29T22:06:22Z"
updated_date: "2026-02-04T02:50:08.291668Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-57752"
- "GHSA-g5qg-72qw-gw5v"
affected_versions:
- "introduced=0.9.9, fixed<14.2.31"
- "introduced=15.0.0, fixed<15.4.5"
fixed_versions:
- "14.2.31"
- "15.4.5"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-g5qg-72qw-gw5v"
---
# Next.js Affected by Cache Key Confusion for Image Optimization API Routes
## 事件层
- Canonical ID: `nextjs--CVE-2025-57752`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-g5qg-72qw-gw5v
- 影响版本: `introduced=0.9.9, fixed<14.2.31, introduced=15.0.0, fixed<15.4.5`
- 修复版本: `14.2.31, 15.4.5`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-57752
- https://github.com/vercel/next.js/pull/82114
- https://github.com/vercel/next.js/commit/6b12c60c61ee80cb0443ccd20de82ca9b4422ddd
- https://github.com/vercel/next.js
- https://vercel.com/changelog/cve-2025-57752
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,95 @@
---
title: "Next.js Improper Middleware Redirect Handling Leads to SSRF"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-08-29T21:33:09Z"
updated_date: "2026-02-04T04:20:45.658010Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-57822"
- "GHSA-4342-x723-ch2f"
affected_versions:
- "introduced=0.9.9, fixed<14.2.32"
- "introduced=15.0.0-canary.0, fixed<15.4.7"
fixed_versions:
- "14.2.32"
- "15.4.7"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "ssrf-url-validation"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-4342-x723-ch2f"
---
# Next.js Improper Middleware Redirect Handling Leads to SSRF
## 事件层
- Canonical ID: `nextjs--CVE-2025-57822`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-4342-x723-ch2f
- 影响版本: `introduced=0.9.9, fixed<14.2.32, introduced=15.0.0-canary.0, fixed<15.4.7`
- 修复版本: `14.2.32, 15.4.7`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-57822
- https://github.com/vercel/next.js/commit/9c9aaed5bb9338ef31b0517ccf0ab4414f2093d8
- https://github.com/vercel/next.js
- https://vercel.com/changelog/cve-2025-57822
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)

查看文件

@@ -0,0 +1,88 @@
---
title: "Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-01-27T19:18:25Z"
updated_date: "2026-02-10T01:28:46.973023Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-59471"
- "GHSA-9g9p-9gw9-jx7f"
affected_versions:
- "introduced=10.0.0, fixed<15.5.10"
- "introduced=15.6.0-canary.0, fixed<16.1.5"
fixed_versions:
- "15.5.10"
- "16.1.5"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-9g9p-9gw9-jx7f"
---
# Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
## 事件层
- Canonical ID: `nextjs--CVE-2025-59471`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-9g9p-9gw9-jx7f
- 影响版本: `introduced=10.0.0, fixed<15.5.10, introduced=15.6.0-canary.0, fixed<16.1.5`
- 修复版本: `15.5.10, 16.1.5`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-59471
- https://github.com/vercel/next.js/commit/500ec83743639addceaede95e95913398975156c
- https://github.com/vercel/next.js/commit/e5b834d208fe0edf64aa26b5d76dcf6a176500ec
- https://github.com/vercel/next.js
- https://github.com/vercel/next.js/releases/tag/v15.5.10
- https://github.com/vercel/next.js/releases/tag/v16.1.5
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,85 @@
---
title: "Next.js has Unbounded Memory Consumption via PPR Resume Endpoint "
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-01-28T15:20:55Z"
updated_date: "2026-02-06T13:13:43.709252Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-59472"
- "GHSA-5f7q-jpqc-wp7h"
affected_versions:
- "introduced=15.0.0-canary.0, fixed<15.6.0-canary.61"
- "introduced=16.0.0-beta.0, fixed<16.1.5"
fixed_versions:
- "15.6.0-canary.61"
- "16.1.5"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-5f7q-jpqc-wp7h"
---
# Next.js has Unbounded Memory Consumption via PPR Resume Endpoint
## 事件层
- Canonical ID: `nextjs--CVE-2025-59472`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-5f7q-jpqc-wp7h
- 影响版本: `introduced=15.0.0-canary.0, fixed<15.6.0-canary.61, introduced=16.0.0-beta.0, fixed<16.1.5`
- 修复版本: `15.6.0-canary.61, 16.1.5`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-59472
- https://github.com/vercel/next.js
- https://vercel.com/changelog/summaries-of-cve-2025-59471-and-cve-2025-59472
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,103 @@
---
title: "Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-12-12T17:21:57Z"
updated_date: "2026-02-04T02:46:38.768104Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "GHSA-5j59-xgg2-r9c4"
affected_versions:
- "introduced=13.3.1-canary.0, fixed<14.2.35"
- "introduced=15.0.6, fixed<15.0.7"
- "introduced=15.1.10, fixed<15.1.11"
- "introduced=15.2.7, fixed<15.2.8"
- "introduced=15.3.7, fixed<15.3.8"
- "introduced=15.4.9, fixed<15.4.10"
- "introduced=15.5.8, fixed<15.5.9"
- "introduced=15.6.0-canary.59, fixed<15.6.0-canary.60"
- "introduced=16.0.9, fixed<16.0.10"
- "introduced=16.1.0-canary.17, fixed<16.1.0-canary.19"
fixed_versions:
- "14.2.35"
- "15.0.7"
- "15.1.11"
- "15.2.8"
- "15.3.8"
- "15.4.10"
- "15.5.9"
- "15.6.0-canary.60"
- "16.0.10"
- "16.1.0-canary.19"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-5j59-xgg2-r9c4"
---
# Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
## 事件层
- Canonical ID: `nextjs--GHSA-5j59-xgg2-r9c4`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-5j59-xgg2-r9c4
- 影响版本: `introduced=13.3.1-canary.0, fixed<14.2.35, introduced=15.0.6, fixed<15.0.7, introduced=15.1.10, fixed<15.1.11, introduced=15.2.7, fixed<15.2.8, introduced=15.3.7, fixed<15.3.8, introduced=15.4.9, fixed<15.4.10, introduced=15.5.8, fixed<15.5.9, introduced=15.6.0-canary.59, fixed<15.6.0-canary.60, introduced=16.0.9, fixed<16.0.10, introduced=16.1.0-canary.17, fixed<16.1.0-canary.19`
- 修复版本: `14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 15.6.0-canary.60, 16.0.10, 16.1.0-canary.19`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-67779
- https://github.com/vercel/next.js
- https://nextjs.org/blog/security-update-2025-12-11
- https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
- https://www.cve.org/CVERecord?id=CVE-2025-55184
- https://www.facebook.com/security/advisories/cve-2025-67779
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,104 @@
---
title: "Next.js is vulnerable to RCE in React flight protocol"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-12-03T19:07:11Z"
updated_date: "2026-02-04T03:45:15.823345Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "GHSA-9qr9-h5gf-34mp"
affected_versions:
- "introduced=14.3.0-canary.77, fixed<15.0.5"
- "introduced=15.1.0-canary.0, fixed<15.1.9"
- "introduced=15.2.0-canary.0, fixed<15.2.6"
- "introduced=15.3.0-canary.0, fixed<15.3.6"
- "introduced=15.4.0-canary.0, fixed<15.4.8"
- "introduced=15.5.0-canary.0, fixed<15.5.7"
- "introduced=16.0.0-canary.0, fixed<16.0.7"
fixed_versions:
- "15.0.5"
- "15.1.9"
- "15.2.6"
- "15.3.6"
- "15.4.8"
- "15.5.7"
- "16.0.7"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
primary_source: "https://github.com/facebook/react/security/advisories/GHSA-fv66-9v8q-g76r"
---
# Next.js is vulnerable to RCE in React flight protocol
## 事件层
- Canonical ID: `nextjs--GHSA-9qr9-h5gf-34mp`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/facebook/react/security/advisories/GHSA-fv66-9v8q-g76r
- 影响版本: `introduced=14.3.0-canary.77, fixed<15.0.5, introduced=15.1.0-canary.0, fixed<15.1.9, introduced=15.2.0-canary.0, fixed<15.2.6, introduced=15.3.0-canary.0, fixed<15.3.6, introduced=15.4.0-canary.0, fixed<15.4.8, introduced=15.5.0-canary.0, fixed<15.5.7, introduced=16.0.0-canary.0, fixed<16.0.7`
- 修复版本: `15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7`
## 其他来源
- https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp
- https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-fmh4-wr37-44fp
- https://nvd.nist.gov/vuln/detail/CVE-2025-55182
- https://github.com/vercel/next.js
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)

查看文件

@@ -0,0 +1,117 @@
---
title: "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-01-28T15:38:01Z"
updated_date: "2026-02-13T00:43:52.836085Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "GHSA-h25m-26qc-wcjf"
affected_versions:
- "introduced=13.0.0, fixed<15.0.8"
- "introduced=15.1.1-canary.0, fixed<15.1.12"
- "introduced=15.2.0-canary.0, fixed<15.2.9"
- "introduced=15.3.0-canary.0, fixed<15.3.9"
- "introduced=15.4.0-canary.0, fixed<15.4.11"
- "introduced=15.5.1-canary.0, fixed<15.5.10"
- "introduced=15.6.0-canary.0, fixed<15.6.0-canary.61"
- "introduced=16.0.0-beta.0, fixed<16.0.11"
- "introduced=16.1.0-canary.0, fixed<16.1.5"
fixed_versions:
- "15.0.8"
- "15.1.12"
- "15.2.9"
- "15.3.9"
- "15.4.11"
- "15.5.10"
- "15.6.0-canary.61"
- "16.0.11"
- "16.1.5"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
- "deserialization-safety"
primary_source: "https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg"
---
# Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
## 事件层
- Canonical ID: `nextjs--GHSA-h25m-26qc-wcjf`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg
- 影响版本: `introduced=13.0.0, fixed<15.0.8, introduced=15.1.1-canary.0, fixed<15.1.12, introduced=15.2.0-canary.0, fixed<15.2.9, introduced=15.3.0-canary.0, fixed<15.3.9, introduced=15.4.0-canary.0, fixed<15.4.11, introduced=15.5.1-canary.0, fixed<15.5.10, introduced=15.6.0-canary.0, fixed<15.6.0-canary.61, introduced=16.0.0-beta.0, fixed<16.0.11, introduced=16.1.0-canary.0, fixed<16.1.5`
- 修复版本: `15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5`
## 其他来源
- https://github.com/vercel/next.js/security/advisories/GHSA-h25m-26qc-wcjf
- https://nvd.nist.gov/vuln/detail/CVE-2026-23864
- https://github.com/vercel/next.js
- https://vercel.com/changelog/summary-of-cve-2026-23864
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:deserialization-safety](/Users/x/websafe/05-defense/secure-code/javascript-typescript/deserialization-safety.md)
- [nodejs:deserialization-safety](/Users/x/websafe/05-defense/secure-code/nodejs/deserialization-safety.md)
- [java:deserialization-safety](/Users/x/websafe/05-defense/secure-code/java/deserialization-safety.md)
- [php:deserialization-safety](/Users/x/websafe/05-defense/secure-code/php/deserialization-safety.md)
- [python:deserialization-safety](/Users/x/websafe/05-defense/secure-code/python/deserialization-safety.md)
- [ruby:deserialization-safety](/Users/x/websafe/05-defense/secure-code/ruby/deserialization-safety.md)
- [csharp:deserialization-safety](/Users/x/websafe/05-defense/secure-code/csharp/deserialization-safety.md)
- [go:deserialization-safety](/Users/x/websafe/05-defense/secure-code/go/deserialization-safety.md)

查看文件

@@ -0,0 +1,109 @@
---
title: "Next Vulnerable to Denial of Service with Server Components"
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-12-11T22:49:27Z"
updated_date: "2026-02-04T03:55:54.855562Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "GHSA-mwv6-3258-q52c"
affected_versions:
- "introduced=13.3.0, fixed<14.2.34"
- "introduced=15.0.0-canary.0, fixed<15.0.6"
- "introduced=15.1.1-canary.0, fixed<15.1.10"
- "introduced=15.2.0-canary.0, fixed<15.2.7"
- "introduced=15.3.0-canary.0, fixed<15.3.7"
- "introduced=15.4.0-canary.0, fixed<15.4.9"
- "introduced=15.5.1-canary.0, fixed<15.5.8"
- "introduced=15.6.0-canary.0, fixed<15.6.0-canary.59"
- "introduced=16.0.0-beta.0, fixed<16.0.9"
- "introduced=16.1.0-canary.0, fixed<16.1.0-canary.17"
fixed_versions:
- "14.2.34"
- "15.0.6"
- "15.1.10"
- "15.2.7"
- "15.3.7"
- "15.4.9"
- "15.5.8"
- "15.6.0-canary.59"
- "16.0.9"
- "16.1.0-canary.17"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-mwv6-3258-q52c"
---
# Next Vulnerable to Denial of Service with Server Components
## 事件层
- Canonical ID: `nextjs--GHSA-mwv6-3258-q52c`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-mwv6-3258-q52c
- 影响版本: `introduced=13.3.0, fixed<14.2.34, introduced=15.0.0-canary.0, fixed<15.0.6, introduced=15.1.1-canary.0, fixed<15.1.10, introduced=15.2.0-canary.0, fixed<15.2.7, introduced=15.3.0-canary.0, fixed<15.3.7, introduced=15.4.0-canary.0, fixed<15.4.9, introduced=15.5.1-canary.0, fixed<15.5.8, introduced=15.6.0-canary.0, fixed<15.6.0-canary.59, introduced=16.0.0-beta.0, fixed<16.0.9, introduced=16.1.0-canary.0, fixed<16.1.0-canary.17`
- 修复版本: `14.2.34, 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17`
## 其他来源
- https://github.com/vercel/next.js
- https://nextjs.org/blog/security-update-2025-12-11
- https://www.cve.org/CVERecord?id=CVE-2025-55184
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)

查看文件

@@ -0,0 +1,107 @@
---
title: "Next Server Actions Source Code Exposure "
system_id: "nextjs"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-12-11T22:49:56Z"
updated_date: "2026-02-04T02:51:40.627151Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "GHSA-w37m-7fhw-fmv9"
affected_versions:
- "introduced=15.0.0-canary.0, fixed<15.0.6"
- "introduced=15.1.1-canary.0, fixed<15.1.10"
- "introduced=15.2.0-canary.0, fixed<15.2.7"
- "introduced=15.3.0-canary.0, fixed<15.3.7"
- "introduced=15.4.0-canary.0, fixed<15.4.9"
- "introduced=15.5.1-canary.0, fixed<15.5.8"
- "introduced=15.6.0-canary.0, fixed<15.6.0-canary.59"
- "introduced=16.0.0-beta.0, fixed<16.0.9"
- "introduced=16.1.0-canary.0, fixed<16.1.0-canary.17"
fixed_versions:
- "15.0.6"
- "15.1.10"
- "15.2.7"
- "15.3.7"
- "15.4.9"
- "15.5.8"
- "15.6.0-canary.59"
- "16.0.9"
- "16.1.0-canary.17"
secure_code_topics:
- "authz-server-side-recheck"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
primary_source: "https://github.com/vercel/next.js/security/advisories/GHSA-w37m-7fhw-fmv9"
---
# Next Server Actions Source Code Exposure
## 事件层
- Canonical ID: `nextjs--GHSA-w37m-7fhw-fmv9`
- 系统: `nextjs`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vercel/next.js/security/advisories/GHSA-w37m-7fhw-fmv9
- 影响版本: `introduced=15.0.0-canary.0, fixed<15.0.6, introduced=15.1.1-canary.0, fixed<15.1.10, introduced=15.2.0-canary.0, fixed<15.2.7, introduced=15.3.0-canary.0, fixed<15.3.7, introduced=15.4.0-canary.0, fixed<15.4.9, introduced=15.5.1-canary.0, fixed<15.5.8, introduced=15.6.0-canary.0, fixed<15.6.0-canary.59, introduced=16.0.0-beta.0, fixed<16.0.9, introduced=16.1.0-canary.0, fixed<16.1.0-canary.17`
- 修复版本: `15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 15.6.0-canary.59, 16.0.9, 16.1.0-canary.17`
## 其他来源
- https://github.com/vercel/next.js
- https://nextjs.org/blog/security-update-2025-12-11
- https://www.cve.org/CVERecord?id=CVE-2025-55183
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/javascript-typescript/authz-server-side-recheck.md)
- [nodejs:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/nodejs/authz-server-side-recheck.md)
- [java:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/java/authz-server-side-recheck.md)
- [php:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/php/authz-server-side-recheck.md)
- [python:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/python/authz-server-side-recheck.md)
- [ruby:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/ruby/authz-server-side-recheck.md)
- [csharp:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/csharp/authz-server-side-recheck.md)
- [go:authz-server-side-recheck](/Users/x/websafe/05-defense/secure-code/go/authz-server-side-recheck.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)

查看文件

@@ -0,0 +1,30 @@
# Node.js
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `nodejs`
- 分类: `frameworks`
- 覆盖策略: `history-full`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Node.js Security Releases](https://nodejs.org/en/blog/vulnerability) (mode=core)
- `official` [CISA KEV Node.js](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Node.js
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `history-full`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/nodejs`
- 修复主题: ssrf-url-validation, request-smuggling-boundary, dependency-upgrade-policy
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/nodejs/INDEX.md)
- Registry 统计: [nodejs.json](/Users/x/websafe/08-threat-intel/registry/systems/nodejs.json)

查看文件

@@ -0,0 +1,31 @@
# Nuxt
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `nuxt`
- 分类: `frameworks`
- 覆盖策略: `history-full`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Nuxt Security](https://github.com/nuxt/nuxt/security/advisories) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Nuxt](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Nuxt
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `history-full`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/nuxt`
- 修复主题: authz-server-side-recheck, proxy-trust-boundary, token-cookie-storage
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/nuxt/INDEX.md)
- Registry 统计: [nuxt.json](/Users/x/websafe/08-threat-intel/registry/systems/nuxt.json)

查看文件

@@ -0,0 +1,30 @@
# Ruby on Rails
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `rails`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=rubygems; mode=core)
- `official` [OSV Rails](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Ruby on Rails
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/rails`
- 修复主题: xss-output-encoding, file-upload-validation, authz-server-side-recheck
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/rails/INDEX.md)
- Registry 统计: [rails.json](/Users/x/websafe/08-threat-intel/registry/systems/rails.json)

查看文件

@@ -0,0 +1,31 @@
# React
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `react`
- 分类: `frameworks`
- 覆盖策略: `history-full`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub React Advisories](https://github.com/facebook/react/security/advisories) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV React](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# React
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `history-full`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/react`
- 修复主题: xss-output-encoding, dom-sink-hardening, csp-trusted-types
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/react/INDEX.md)
- Registry 统计: [react.json](/Users/x/websafe/08-threat-intel/registry/systems/react.json)

查看文件

@@ -0,0 +1,30 @@
# Spring Boot
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `spring-boot`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Spring Security Advisories](https://spring.io/security) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=maven; mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Spring Boot
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/spring-boot`
- 修复主题: proxy-trust-boundary, authz-server-side-recheck
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/spring-boot/INDEX.md)
- Registry 统计: [spring-boot.json](/Users/x/websafe/08-threat-intel/registry/systems/spring-boot.json)

查看文件

@@ -0,0 +1,30 @@
# Spring Framework
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `spring-framework`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Spring Security Advisories](https://spring.io/security) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=maven; mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Spring Framework
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/spring-framework`
- 修复主题: authz-server-side-recheck, path-traversal-guard, deserialization-safety
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/spring-framework/INDEX.md)
- Registry 统计: [spring-framework.json](/Users/x/websafe/08-threat-intel/registry/systems/spring-framework.json)

查看文件

@@ -0,0 +1,30 @@
# Spring Security
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `spring-security`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Spring Security Advisories](https://spring.io/security) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=maven; mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Spring Security
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/spring-security`
- 修复主题: authz-server-side-recheck, token-cookie-storage, proxy-trust-boundary
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/spring-security/INDEX.md)
- Registry 统计: [spring-security.json](/Users/x/websafe/08-threat-intel/registry/systems/spring-security.json)

查看文件

@@ -0,0 +1,30 @@
# SvelteKit
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `sveltekit`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV SvelteKit](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# SvelteKit
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/sveltekit`
- 修复主题: authz-server-side-recheck, token-cookie-storage
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/sveltekit/INDEX.md)
- Registry 统计: [sveltekit.json](/Users/x/websafe/08-threat-intel/registry/systems/sveltekit.json)

查看文件

@@ -0,0 +1,30 @@
# Symfony
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `symfony`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `0`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `0`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=composer; mode=core)
- `official` [OSV Symfony](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |

查看文件

@@ -0,0 +1,16 @@
# Symfony
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/symfony`
- 修复主题: xss-output-encoding, authz-server-side-recheck, path-traversal-guard
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/symfony/INDEX.md)
- Registry 统计: [symfony.json](/Users/x/websafe/08-threat-intel/registry/systems/symfony.json)

查看文件

@@ -0,0 +1,43 @@
# Undici
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `undici`
- 分类: `frameworks`
- 覆盖策略: `rolling-24m`
- 总案例数: `14`
- 近 30 天新增/更新: `7`
- 重点 Markdown 案例数: `14`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Undici](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression | `low` | `generated` | `official` | `2026-03-13T20:54:25.563997Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-1526.md) |
| Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation | `low` | `generated` | `official` | `2026-03-13T20:54:26.149214Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-2229.md) |
| Undici has CRLF Injection in undici via `upgrade` option | `low` | `generated` | `official` | `2026-03-13T20:54:25.572106Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-1527.md) |
| Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS | `low` | `generated` | `official` | `2026-03-13T20:54:25.417862Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-2581.md) |
| Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client | `low` | `generated` | `official` | `2026-03-14T09:17:45.838435Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-1528.md) |
| Undici has an HTTP Request/Response Smuggling issue | `low` | `generated` | `official` | `2026-03-14T09:19:54.772219Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-1525.md) |
| Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion | `low` | `generated` | `official` | `2026-02-04T02:56:17.456091Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2026-22036.md) |
| undici Denial of Service attack via bad certificate data | `low` | `generated` | `official` | `2026-02-06T22:08:08.311705Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2025-47279.md) |
| Use of Insufficiently Random Values in undici | `low` | `generated` | `official` | `2026-02-04T02:29:26.373390Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2025-22150.md) |
| Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect | `low` | `generated` | `official` | `2025-11-04T19:44:42Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2024-30261.md) |
| Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline | `low` | `generated` | `official` | `2025-11-04T19:44:28Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2024-30260.md) |
| Undici's cookie header not cleared on cross-origin redirect in fetch | `low` | `generated` | `official` | `2026-02-04T02:35:56.289390Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2023-45143.md) |
| undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect | `low` | `generated` | `official` | `2026-02-04T03:02:08.652391Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2022-31151.md) |
| ProxyAgent vulnerable to MITM | `low` | `generated` | `official` | `2026-03-13T22:15:23.541247Z` | [link](/Users/x/websafe/07-framework-security/frameworks/undici/cases/undici-cve-2022-32210.md) |

查看文件

@@ -0,0 +1,16 @@
# Undici
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `rolling-24m`
- Advisory 模式: core
- 输出目录: `07-framework-security/frameworks/undici`
- 修复主题: ssrf-url-validation, proxy-trust-boundary
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/undici/INDEX.md)
- Registry 统计: [undici.json](/Users/x/websafe/08-threat-intel/registry/systems/undici.json)

查看文件

@@ -0,0 +1,98 @@
---
title: "undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2022-07-21T20:31:05Z"
updated_date: "2026-02-04T03:02:08.652391Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2022-31151"
- "GHSA-q768-x9m6-m9qp"
affected_versions:
- "introduced=0, fixed<5.8.0"
fixed_versions:
- "5.8.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
- "token-cookie-storage"
- "dependency-upgrade-policy"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp"
---
# undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
## 事件层
- Canonical ID: `undici--CVE-2022-31151`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp
- 影响版本: `introduced=0, fixed<5.8.0`
- 修复版本: `5.8.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2022-31151
- https://github.com/nodejs/undici/issues/872
- https://github.com/nodejs/undici/pull/1441
- https://github.com/nodejs/undici/commit/0a5bee9465e627be36bac88edf7d9bbc9626126d
- https://hackerone.com/reports/1635514
- https://github.com/nodejs/undici
- https://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189
- https://github.com/nodejs/undici/releases/tag/v5.8.0
- https://security.netapp.com/advisory/ntap-20220909-0006
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)

查看文件

@@ -0,0 +1,74 @@
---
title: "ProxyAgent vulnerable to MITM"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2022-06-17T01:02:29Z"
updated_date: "2026-03-13T22:15:23.541247Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2022-32210"
- "GHSA-pgw7-wx7w-2w33"
affected_versions:
- "introduced=4.8.2, fixed<5.5.1"
fixed_versions:
- "5.5.1"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-pgw7-wx7w-2w33"
---
# ProxyAgent vulnerable to MITM
## 事件层
- Canonical ID: `undici--CVE-2022-32210`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-pgw7-wx7w-2w33
- 影响版本: `introduced=4.8.2, fixed<5.5.1`
- 修复版本: `5.5.1`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2022-32210
- https://hackerone.com/reports/1583680
- https://github.com/nodejs/undici
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,92 @@
---
title: "Undici's cookie header not cleared on cross-origin redirect in fetch"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2023-10-16T14:05:37Z"
updated_date: "2026-02-04T02:35:56.289390Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2023-45143"
- "GHSA-wqq4-5wpv-mx2g"
affected_versions:
- "introduced=0, fixed<5.26.2"
fixed_versions:
- "5.26.2"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
- "token-cookie-storage"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp"
---
# Undici's cookie header not cleared on cross-origin redirect in fetch
## 事件层
- Canonical ID: `undici--CVE-2023-45143`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-q768-x9m6-m9qp
- 影响版本: `introduced=0, fixed<5.26.2`
- 修复版本: `5.26.2`
## 其他来源
- https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g
- https://nvd.nist.gov/vuln/detail/CVE-2023-45143
- https://github.com/nodejs/undici/commit/e041de359221ebeae04c469e8aff4145764e6d76
- https://hackerone.com/reports/2166948
- https://github.com/nodejs/undici
- https://github.com/nodejs/undici/releases/tag/v5.26.2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)

查看文件

@@ -0,0 +1,82 @@
---
title: "Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-04-04T14:20:39Z"
updated_date: "2025-11-04T19:44:28Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-30260"
- "GHSA-m4v8-wqvr-p9f7"
affected_versions:
- "introduced=0, fixed<5.28.4"
- "introduced=6.0.0, fixed<6.11.1"
fixed_versions:
- "5.28.4"
- "6.11.1"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7"
---
# Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
## 事件层
- Canonical ID: `undici--CVE-2024-30260`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7
- 影响版本: `introduced=0, fixed<5.28.4, introduced=6.0.0, fixed<6.11.1`
- 修复版本: `5.28.4, 6.11.1`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-30260
- https://github.com/nodejs/undici/commit/64e3402da4e032e68de46acb52800c9a06aaea3f
- https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75
- https://hackerone.com/reports/2408074
- https://github.com/nodejs/undici
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E
- https://security.netapp.com/advisory/ntap-20240905-0008
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,82 @@
---
title: "Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-04-04T14:20:54Z"
updated_date: "2025-11-04T19:44:42Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-30261"
- "GHSA-9qxr-qj54-h672"
affected_versions:
- "introduced=0, fixed<5.28.4"
- "introduced=6.0.0, fixed<6.11.1"
fixed_versions:
- "5.28.4"
- "6.11.1"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672"
---
# Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
## 事件层
- Canonical ID: `undici--CVE-2024-30261`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672
- 影响版本: `introduced=0, fixed<5.28.4, introduced=6.0.0, fixed<6.11.1`
- 修复版本: `5.28.4, 6.11.1`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-30261
- https://github.com/nodejs/undici/commit/2b39440bd9ded841c93dd72138f3b1763ae26055
- https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3
- https://hackerone.com/reports/2377760
- https://github.com/nodejs/undici
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E
- https://security.netapp.com/advisory/ntap-20240905-0008
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,83 @@
---
title: "Use of Insufficiently Random Values in undici"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-01-21T21:10:47Z"
updated_date: "2026-02-04T02:29:26.373390Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-22150"
- "GHSA-c76h-2ccp-4975"
affected_versions:
- "introduced=4.5.0, fixed<5.28.5"
- "introduced=6.0.0, fixed<6.21.1"
- "introduced=7.0.0, fixed<7.2.3"
fixed_versions:
- "5.28.5"
- "6.21.1"
- "7.2.3"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975"
---
# Use of Insufficiently Random Values in undici
## 事件层
- Canonical ID: `undici--CVE-2025-22150`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975
- 影响版本: `introduced=4.5.0, fixed<5.28.5, introduced=6.0.0, fixed<6.21.1, introduced=7.0.0, fixed<7.2.3`
- 修复版本: `5.28.5, 6.21.1, 7.2.3`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-22150
- https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0
- https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a
- https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385
- https://hackerone.com/reports/2913312
- https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f
- https://github.com/nodejs/undici
- https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,80 @@
---
title: "undici Denial of Service attack via bad certificate data"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-05-15T14:15:06Z"
updated_date: "2026-02-06T22:08:08.311705Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-47279"
- "GHSA-cxrh-j4jr-qwg3"
affected_versions:
- "introduced=0, fixed<5.29.0"
- "introduced=6.0.0, fixed<6.21.2"
- "introduced=7.0.0, fixed<7.5.0"
fixed_versions:
- "5.29.0"
- "6.21.2"
- "7.5.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3"
---
# undici Denial of Service attack via bad certificate data
## 事件层
- Canonical ID: `undici--CVE-2025-47279`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3
- 影响版本: `introduced=0, fixed<5.29.0, introduced=6.0.0, fixed<6.21.2, introduced=7.0.0, fixed<7.5.0`
- 修复版本: `5.29.0, 6.21.2, 7.5.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-47279
- https://github.com/nodejs/undici/issues/3895
- https://github.com/nodejs/undici/pull/4088
- https://github.com/nodejs/undici/commit/f317618ec28753a4218beccea048bcf89c36db25
- https://github.com/nodejs/undici
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,88 @@
---
title: "Undici has an HTTP Request/Response Smuggling issue"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-03-13T20:07:03Z"
updated_date: "2026-03-14T09:19:54.772219Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-1525"
- "GHSA-2mjp-6q6p-2qxm"
affected_versions:
- "introduced=0, fixed<6.24.0"
- "introduced=7.0.0, fixed<7.24.0"
fixed_versions:
- "6.24.0"
- "7.24.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
- "request-smuggling-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm"
---
# Undici has an HTTP Request/Response Smuggling issue
## 事件层
- Canonical ID: `undici--CVE-2026-1525`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm
- 影响版本: `introduced=0, fixed<6.24.0, introduced=7.0.0, fixed<7.24.0`
- 修复版本: `6.24.0, 7.24.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-1525
- https://hackerone.com/reports/3556037
- https://cna.openjsf.org/security-advisories.html
- https://cwe.mitre.org/data/definitions/444.html
- https://github.com/nodejs/undici
- https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/request-smuggling-boundary.md)
- [nodejs:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/request-smuggling-boundary.md)
- [java:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/java/request-smuggling-boundary.md)
- [php:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/php/request-smuggling-boundary.md)
- [python:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/python/request-smuggling-boundary.md)
- [ruby:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/ruby/request-smuggling-boundary.md)
- [csharp:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/csharp/request-smuggling-boundary.md)
- [go:request-smuggling-boundary](/Users/x/websafe/05-defense/secure-code/go/request-smuggling-boundary.md)

查看文件

@@ -0,0 +1,88 @@
---
title: "Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-03-13T20:41:56Z"
updated_date: "2026-03-13T20:54:25.563997Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-1526"
- "GHSA-vrm6-8vpv-qv8q"
affected_versions:
- "introduced=0, fixed<6.24.0"
- "introduced=7.0.0, fixed<7.24.0"
fixed_versions:
- "6.24.0"
- "7.24.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
- "plugin-extension-trust-policy"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q"
---
# Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
## 事件层
- Canonical ID: `undici--CVE-2026-1526`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-vrm6-8vpv-qv8q
- 影响版本: `introduced=0, fixed<6.24.0, introduced=7.0.0, fixed<7.24.0`
- 修复版本: `6.24.0, 7.24.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-1526
- https://hackerone.com/reports/3481206
- https://cna.openjsf.org/security-advisories.html
- https://datatracker.ietf.org/doc/html/rfc7692
- https://github.com/nodejs/undici
- https://owasp.org/www-community/attacks/Denial_of_Service
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/plugin-extension-trust-policy.md)
- [nodejs:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/nodejs/plugin-extension-trust-policy.md)
- [java:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/java/plugin-extension-trust-policy.md)
- [php:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/php/plugin-extension-trust-policy.md)
- [python:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/python/plugin-extension-trust-policy.md)
- [ruby:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/ruby/plugin-extension-trust-policy.md)
- [csharp:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/csharp/plugin-extension-trust-policy.md)
- [go:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/go/plugin-extension-trust-policy.md)

查看文件

@@ -0,0 +1,77 @@
---
title: "Undici has CRLF Injection in undici via `upgrade` option"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-03-13T20:41:26Z"
updated_date: "2026-03-13T20:54:25.572106Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-1527"
- "GHSA-4992-7rv2-5pvq"
affected_versions:
- "introduced=0, fixed<6.24.0"
- "introduced=7.0.0, fixed<7.24.0"
fixed_versions:
- "6.24.0"
- "7.24.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq"
---
# Undici has CRLF Injection in undici via `upgrade` option
## 事件层
- Canonical ID: `undici--CVE-2026-1527`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq
- 影响版本: `introduced=0, fixed<6.24.0, introduced=7.0.0, fixed<7.24.0`
- 修复版本: `6.24.0, 7.24.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-1527
- https://hackerone.com/reports/3487198
- https://cna.openjsf.org/security-advisories.html
- https://github.com/nodejs/undici
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,77 @@
---
title: "Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-03-13T20:07:26Z"
updated_date: "2026-03-14T09:17:45.838435Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-1528"
- "GHSA-f269-vfmq-vjvj"
affected_versions:
- "introduced=6.0.0, fixed<6.24.0"
- "introduced=7.0.0, fixed<7.24.0"
fixed_versions:
- "6.24.0"
- "7.24.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj"
---
# Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
## 事件层
- Canonical ID: `undici--CVE-2026-1528`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-f269-vfmq-vjvj
- 影响版本: `introduced=6.0.0, fixed<6.24.0, introduced=7.0.0, fixed<7.24.0`
- 修复版本: `6.24.0, 7.24.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-1528
- https://hackerone.com/reports/3537648
- https://cna.openjsf.org/security-advisories.html
- https://github.com/nodejs/undici
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,76 @@
---
title: "Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-01-14T21:06:08Z"
updated_date: "2026-02-04T02:56:17.456091Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-22036"
- "GHSA-g9mf-h72j-4rw9"
affected_versions:
- "introduced=7.0.0, fixed<7.18.2"
- "introduced=0, fixed<6.23.0"
fixed_versions:
- "7.18.2"
- "6.23.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9"
---
# Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
## 事件层
- Canonical ID: `undici--CVE-2026-22036`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9
- 影响版本: `introduced=7.0.0, fixed<7.18.2, introduced=0, fixed<6.23.0`
- 修复版本: `7.18.2, 6.23.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-22036
- https://github.com/nodejs/undici/commit/b04e3cbb569c1596f86c108e9b52c79d8475dcb3
- https://github.com/nodejs/undici
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,88 @@
---
title: "Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-03-13T20:41:41Z"
updated_date: "2026-03-13T20:54:26.149214Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-2229"
- "GHSA-v9p9-hfj2-hcw8"
affected_versions:
- "introduced=0, fixed<6.24.0"
- "introduced=7.0.0, fixed<7.24.0"
fixed_versions:
- "6.24.0"
- "7.24.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
- "plugin-extension-trust-policy"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8"
---
# Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
## 事件层
- Canonical ID: `undici--CVE-2026-2229`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-v9p9-hfj2-hcw8
- 影响版本: `introduced=0, fixed<6.24.0, introduced=7.0.0, fixed<7.24.0`
- 修复版本: `6.24.0, 7.24.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-2229
- https://hackerone.com/reports/3487486
- https://cna.openjsf.org/security-advisories.html
- https://datatracker.ietf.org/doc/html/rfc7692
- https://github.com/nodejs/undici
- https://nodejs.org/api/zlib.html#class-zlibinflateraw
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/plugin-extension-trust-policy.md)
- [nodejs:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/nodejs/plugin-extension-trust-policy.md)
- [java:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/java/plugin-extension-trust-policy.md)
- [php:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/php/plugin-extension-trust-policy.md)
- [python:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/python/plugin-extension-trust-policy.md)
- [ruby:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/ruby/plugin-extension-trust-policy.md)
- [csharp:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/csharp/plugin-extension-trust-policy.md)
- [go:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/go/plugin-extension-trust-policy.md)

查看文件

@@ -0,0 +1,75 @@
---
title: "Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS"
system_id: "undici"
category: "frameworks"
advisory_mode: "core"
published_date: "2026-03-13T20:37:58Z"
updated_date: "2026-03-13T20:54:25.417862Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2026-2581"
- "GHSA-phc3-fgpg-7m6h"
affected_versions:
- "introduced=7.17.0, fixed<7.24.0"
fixed_versions:
- "7.24.0"
secure_code_topics:
- "ssrf-url-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6h"
---
# Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
## 事件层
- Canonical ID: `undici--CVE-2026-2581`
- 系统: `undici`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6h
- 影响版本: `introduced=7.17.0, fixed<7.24.0`
- 修复版本: `7.24.0`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2026-2581
- https://hackerone.com/reports/3513473
- https://cna.openjsf.org/security-advisories.html
- https://github.com/nodejs/undici
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/ssrf-url-validation.md)
- [nodejs:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/nodejs/ssrf-url-validation.md)
- [java:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/java/ssrf-url-validation.md)
- [php:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/php/ssrf-url-validation.md)
- [python:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/python/ssrf-url-validation.md)
- [ruby:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/ruby/ssrf-url-validation.md)
- [csharp:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/csharp/ssrf-url-validation.md)
- [go:ssrf-url-validation](/Users/x/websafe/05-defense/secure-code/go/ssrf-url-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,42 @@
# Vite
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
- 系统 ID: `vite`
- 分类: `frameworks`
- 覆盖策略: `history-full`
- 总案例数: `12`
- 近 30 天新增/更新: `0`
- 重点 Markdown 案例数: `12`
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
## 目标约束
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but ownership or authorization is required`
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 来源
- `official` [Vite Security](https://github.com/vitejs/vite/security/advisories) (mode=core)
- `official` [GitHub Global Advisories](https://github.com/advisories) (ecosystem=npm; mode=core)
- `official` [OSV Vite](https://osv.dev/) (mode=core)
## 案例列表
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|------|--------|------|------------|----------|--------|
| vite allows server.fs.deny bypass via backslash on Windows | `medium` | `generated` | `official` | `2026-02-04T04:13:38.886554Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-62522.md) |
| Vite middleware may serve files starting with the same name with the public directory | `medium` | `generated` | `official` | `2026-02-04T04:33:22.508417Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-58751.md) |
| Vite's `server.fs` settings were not applied to HTML files | `medium` | `generated` | `official` | `2026-02-04T04:35:16.287471Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-58752.md) |
| Vite's server.fs.deny bypassed with /. for files under project root | `medium` | `generated` | `official` | `2026-02-04T03:27:17.681639Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-46565.md) |
| Vite has an `server.fs.deny` bypass with an invalid `request-target` | `medium` | `generated` | `official` | `2026-02-04T04:11:44.900383Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-32395.md) |
| Vite allows server.fs.deny to be bypassed with .svg or relative paths | `low` | `generated` | `official` | `2026-02-04T03:51:38.412061Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-31486.md) |
| Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | `low` | `generated` | `official` | `2026-02-04T04:37:24.129476Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-31125.md) |
| Vite bypasses server.fs.deny when using ?raw?? | `low` | `generated` | `official` | `2026-02-04T03:13:24.371631Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-30208.md) |
| Websites were able to send any requests to the development server and read the response in vite | `low` | `generated` | `official` | `2026-02-04T04:37:03.076966Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2025-24010.md) |
| Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS | `low` | `generated` | `official` | `2026-02-04T04:04:22.977459Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2024-45812.md) |
| Vite's `server.fs.deny` is bypassed when using `?import&raw` | `low` | `generated` | `official` | `2026-02-04T04:05:31.919291Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2024-45811.md) |
| Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem | `low` | `generated` | `official` | `2026-02-04T04:17:01.410592Z` | [link](/Users/x/websafe/07-framework-security/frameworks/vite/cases/vite-cve-2024-23331.md) |

查看文件

@@ -0,0 +1,16 @@
# Vite
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
- 分类: `frameworks`
- 覆盖层级: `history-full`
- Advisory 模式: core, plugin
- 输出目录: `07-framework-security/frameworks/vite`
- 修复主题: dependency-upgrade-policy, file-upload-validation, proxy-trust-boundary
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
- 是否允许公网验证: `yes, but only for owned or authorized targets`
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/frameworks/vite/INDEX.md)
- Registry 统计: [vite.json](/Users/x/websafe/08-threat-intel/registry/systems/vite.json)

查看文件

@@ -0,0 +1,94 @@
---
title: "Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-01-19T21:58:47Z"
updated_date: "2026-02-04T04:17:01.410592Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-23331"
- "GHSA-c24v-8rfc-w8vw"
affected_versions:
- "introduced=2.7.0, fixed<2.9.17"
- "introduced=3.0.0, fixed<3.2.8"
- "introduced=4.0.0, fixed<4.5.2"
- "introduced=5.0.0, fixed<5.0.12"
fixed_versions:
- "2.9.17"
- "3.2.8"
- "4.5.2"
- "5.0.12"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-c24v-8rfc-w8vw"
---
# Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
## 事件层
- Canonical ID: `vite--CVE-2024-23331`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-c24v-8rfc-w8vw
- 影响版本: `introduced=2.7.0, fixed<2.9.17, introduced=3.0.0, fixed<3.2.8, introduced=4.0.0, fixed<4.5.2, introduced=5.0.0, fixed<5.0.12`
- 修复版本: `2.9.17, 3.2.8, 4.5.2, 5.0.12`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2023-34092
- https://nvd.nist.gov/vuln/detail/CVE-2024-23331
- https://github.com/vitejs/vite/commit/0cd769c279724cf27934b1270fbdd45d68217691
- https://github.com/vitejs/vite/commit/91641c4da0a011d4c5352e88fc68389d4e1289a5
- https://github.com/vitejs/vite/commit/a26c87d20f9af306b5ce3ff1648be7fa5146c278
- https://github.com/vitejs/vite/commit/eeec23bbc9d476c54a3a6d36e78455867185a7cb
- https://github.com/vitejs/vite
- https://vitejs.dev/config/server-options.html#server-fs-deny
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,97 @@
---
title: "Vite's `server.fs.deny` is bypassed when using `?import&raw`"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-09-17T18:44:12Z"
updated_date: "2026-02-04T04:05:31.919291Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-45811"
- "GHSA-9cwx-2883-4wfx"
affected_versions:
- "introduced=5.4.0, fixed<5.4.6"
- "introduced=5.3.0, fixed<5.3.6"
- "introduced=5.2.0, fixed<5.2.14"
- "introduced=4.0.0, fixed<4.5.4"
- "introduced=0, fixed<3.2.11"
- "introduced=5.0.0, fixed<5.1.8"
fixed_versions:
- "5.4.6"
- "5.3.6"
- "5.2.14"
- "4.5.4"
- "3.2.11"
- "5.1.8"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-9cwx-2883-4wfx"
---
# Vite's `server.fs.deny` is bypassed when using `?import&raw`
## 事件层
- Canonical ID: `vite--CVE-2024-45811`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-9cwx-2883-4wfx
- 影响版本: `introduced=5.4.0, fixed<5.4.6, introduced=5.3.0, fixed<5.3.6, introduced=5.2.0, fixed<5.2.14, introduced=4.0.0, fixed<4.5.4, introduced=0, fixed<3.2.11, introduced=5.0.0, fixed<5.1.8`
- 修复版本: `5.4.6, 5.3.6, 5.2.14, 4.5.4, 3.2.11, 5.1.8`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2024-45811
- https://github.com/vitejs/vite/commit/4573a6fd6f1b097fb7296a3e135e0646b996b249
- https://github.com/vitejs/vite/commit/6820bb3b9a54334f3268fc5ee1e967d2e1c0db34
- https://github.com/vitejs/vite/commit/8339d7408668686bae56eaccbfdc7b87612904bd
- https://github.com/vitejs/vite/commit/a6da45082b6e73ddfdcdcc06bb5414f976a388d6
- https://github.com/vitejs/vite/commit/b901438f99e667f76662840826eec91c8ab3b3e7
- https://github.com/vitejs/vite
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,119 @@
---
title: "Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2024-09-17T19:28:01Z"
updated_date: "2026-02-04T04:04:22.977459Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2024-45812"
- "GHSA-64vr-g452-qvp3"
affected_versions:
- "introduced=5.4.0, fixed<5.4.6"
- "introduced=5.3.0, fixed<5.3.6"
- "introduced=5.2.0, fixed<5.2.14"
- "introduced=4.0.0, fixed<4.5.4"
- "introduced=0, fixed<3.2.11"
- "introduced=5.0.0, fixed<5.1.8"
fixed_versions:
- "5.4.6"
- "5.3.6"
- "5.2.14"
- "4.5.4"
- "3.2.11"
- "5.1.8"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
- "xss-output-encoding"
- "plugin-extension-trust-policy"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-64vr-g452-qvp3"
---
# Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS
## 事件层
- Canonical ID: `vite--CVE-2024-45812`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-64vr-g452-qvp3
- 影响版本: `introduced=5.4.0, fixed<5.4.6, introduced=5.3.0, fixed<5.3.6, introduced=5.2.0, fixed<5.2.14, introduced=4.0.0, fixed<4.5.4, introduced=0, fixed<3.2.11, introduced=5.0.0, fixed<5.1.8`
- 修复版本: `5.4.6, 5.3.6, 5.2.14, 4.5.4, 3.2.11, 5.1.8`
## 其他来源
- https://github.com/webpack/webpack/security/advisories/GHSA-4vvj-4cpr-p986
- https://nvd.nist.gov/vuln/detail/CVE-2024-45812
- https://github.com/vitejs/vite/commit/179b17773cf35c73ddb041f9e6c703fd9f3126af
- https://github.com/vitejs/vite/commit/2691bb3ff6b073b41fb9046909e1e03a74e36675
- https://github.com/vitejs/vite/commit/2ddd8541ec3b2d2e5b698749e0f2362ef28056bd
- https://github.com/vitejs/vite/commit/ade1d89660e17eedfd35652165b0c26905259fad
- https://github.com/vitejs/vite/commit/e8127166979e7ace6eeaa2c3b733c8994caa31f3
- https://github.com/vitejs/vite/commit/ebb94c5b3bf41950f45562595adec117a4d0ba5e
- https://github.com/vitejs/vite
- https://research.securitum.com/xss-in-amp4email-dom-clobbering
- https://scnps.co/papers/sp23_domclob.pdf
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/javascript-typescript/xss-output-encoding.md)
- [nodejs:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/nodejs/xss-output-encoding.md)
- [java:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/java/xss-output-encoding.md)
- [php:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/php/xss-output-encoding.md)
- [python:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/python/xss-output-encoding.md)
- [ruby:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/ruby/xss-output-encoding.md)
- [csharp:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/csharp/xss-output-encoding.md)
- [go:xss-output-encoding](/Users/x/websafe/05-defense/secure-code/go/xss-output-encoding.md)
- [javascript-typescript:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/plugin-extension-trust-policy.md)
- [nodejs:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/nodejs/plugin-extension-trust-policy.md)
- [java:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/java/plugin-extension-trust-policy.md)
- [php:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/php/plugin-extension-trust-policy.md)
- [python:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/python/plugin-extension-trust-policy.md)
- [ruby:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/ruby/plugin-extension-trust-policy.md)
- [csharp:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/csharp/plugin-extension-trust-policy.md)
- [go:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/go/plugin-extension-trust-policy.md)

查看文件

@@ -0,0 +1,113 @@
---
title: "Websites were able to send any requests to the development server and read the response in vite"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-01-21T19:52:55Z"
updated_date: "2026-02-04T04:37:03.076966Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-24010"
- "GHSA-vg6x-rcgg-rjx6"
affected_versions:
- "introduced=6.0.0, fixed<6.0.9"
- "introduced=5.0.0, fixed<5.4.12"
- "introduced=0, fixed<4.5.6"
fixed_versions:
- "6.0.9"
- "5.4.12"
- "4.5.6"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
- "dom-sink-hardening"
- "token-cookie-storage"
- "plugin-extension-trust-policy"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6"
---
# Websites were able to send any requests to the development server and read the response in vite
## 事件层
- Canonical ID: `vite--CVE-2025-24010`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-vg6x-rcgg-rjx6
- 影响版本: `introduced=6.0.0, fixed<6.0.9, introduced=5.0.0, fixed<5.4.12, introduced=0, fixed<4.5.6`
- 修复版本: `6.0.9, 5.4.12, 4.5.6`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-24010
- https://github.com/vitejs/vite
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dom-sink-hardening.md)
- [nodejs:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/nodejs/dom-sink-hardening.md)
- [java:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/java/dom-sink-hardening.md)
- [php:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/php/dom-sink-hardening.md)
- [python:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/python/dom-sink-hardening.md)
- [ruby:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/ruby/dom-sink-hardening.md)
- [csharp:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/csharp/dom-sink-hardening.md)
- [go:dom-sink-hardening](/Users/x/websafe/05-defense/secure-code/go/dom-sink-hardening.md)
- [javascript-typescript:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/javascript-typescript/token-cookie-storage.md)
- [nodejs:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/nodejs/token-cookie-storage.md)
- [java:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/java/token-cookie-storage.md)
- [php:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/php/token-cookie-storage.md)
- [python:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/python/token-cookie-storage.md)
- [ruby:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/ruby/token-cookie-storage.md)
- [csharp:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/csharp/token-cookie-storage.md)
- [go:token-cookie-storage](/Users/x/websafe/05-defense/secure-code/go/token-cookie-storage.md)
- [javascript-typescript:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/plugin-extension-trust-policy.md)
- [nodejs:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/nodejs/plugin-extension-trust-policy.md)
- [java:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/java/plugin-extension-trust-policy.md)
- [php:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/php/plugin-extension-trust-policy.md)
- [python:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/python/plugin-extension-trust-policy.md)
- [ruby:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/ruby/plugin-extension-trust-policy.md)
- [csharp:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/csharp/plugin-extension-trust-policy.md)
- [go:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/go/plugin-extension-trust-policy.md)

查看文件

@@ -0,0 +1,95 @@
---
title: "Vite bypasses server.fs.deny when using ?raw??"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-03-25T14:00:02Z"
updated_date: "2026-02-04T03:13:24.371631Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-30208"
- "GHSA-x574-m823-4x7w"
affected_versions:
- "introduced=6.2.0, fixed<6.2.3"
- "introduced=6.1.0, fixed<6.1.2"
- "introduced=6.0.0, fixed<6.0.12"
- "introduced=5.0.0, fixed<5.4.15"
- "introduced=0, fixed<4.5.10"
fixed_versions:
- "6.2.3"
- "6.1.2"
- "6.0.12"
- "5.4.15"
- "4.5.10"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-x574-m823-4x7w"
---
# Vite bypasses server.fs.deny when using ?raw??
## 事件层
- Canonical ID: `vite--CVE-2025-30208`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-x574-m823-4x7w
- 影响版本: `introduced=6.2.0, fixed<6.2.3, introduced=6.1.0, fixed<6.1.2, introduced=6.0.0, fixed<6.0.12, introduced=5.0.0, fixed<5.4.15, introduced=0, fixed<4.5.10`
- 修复版本: `6.2.3, 6.1.2, 6.0.12, 5.4.15, 4.5.10`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-30208
- https://github.com/vitejs/vite/commit/315695e9d97cc6cfa7e6d9e0229fb50cdae3d9f4
- https://github.com/vitejs/vite/commit/80381c38d6f068b12e6e928cd3c616bd1d64803c
- https://github.com/vitejs/vite/commit/807d7f06d33ab49c48a2a3501da3eea1906c0d41
- https://github.com/vitejs/vite/commit/92ca12dc79118bf66f2b32ff81ed09e0d0bd07ca
- https://github.com/vitejs/vite/commit/f234b5744d8b74c95535a7b82cc88ed2144263c1
- https://github.com/vitejs/vite
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,92 @@
---
title: "Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-03-31T17:31:54Z"
updated_date: "2026-02-04T04:37:24.129476Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-31125"
- "GHSA-4r4m-qw57-chr8"
affected_versions:
- "introduced=6.2.0, fixed<6.2.4"
- "introduced=6.1.0, fixed<6.1.3"
- "introduced=6.0.0, fixed<6.0.13"
- "introduced=5.0.0, fixed<5.4.16"
- "introduced=0, fixed<4.5.11"
fixed_versions:
- "6.2.4"
- "6.1.3"
- "6.0.13"
- "5.4.16"
- "4.5.11"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8"
---
# Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
## 事件层
- Canonical ID: `vite--CVE-2025-31125`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-4r4m-qw57-chr8
- 影响版本: `introduced=6.2.0, fixed<6.2.4, introduced=6.1.0, fixed<6.1.3, introduced=6.0.0, fixed<6.0.13, introduced=5.0.0, fixed<5.4.16, introduced=0, fixed<4.5.11`
- 修复版本: `6.2.4, 6.1.3, 6.0.13, 5.4.16, 4.5.11`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-31125
- https://github.com/vitejs/vite/commit/59673137c45ac2bcfad1170d954347c1a17ab949
- https://github.com/vitejs/vite
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31125
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)

查看文件

@@ -0,0 +1,101 @@
---
title: "Vite allows server.fs.deny to be bypassed with .svg or relative paths"
system_id: "vite"
category: "frameworks"
advisory_mode: "core"
published_date: "2025-04-04T14:20:05Z"
updated_date: "2026-02-04T03:51:38.412061Z"
severity: "low"
exploit_status: "unknown"
source_confidence: "official"
target_types:
- "lab-local"
- "lab-public"
- "authorized-third-party"
allow_public_validation: "yes, with ownership or explicit authorization"
authorization_prerequisite: "asset ownership proof or explicit written authorization"
minimal_validation: "read-only probe, controlled payload, reversible test"
aliases:
- "CVE-2025-31486"
- "GHSA-xcj6-pq6g-qj4x"
affected_versions:
- "introduced=6.2.0, fixed<6.2.5"
- "introduced=6.1.0, fixed<6.1.4"
- "introduced=6.0.0, fixed<6.0.14"
- "introduced=5.0.0, fixed<5.4.17"
- "introduced=0, fixed<4.5.12"
fixed_versions:
- "6.2.5"
- "6.1.4"
- "6.0.14"
- "5.4.17"
- "4.5.12"
secure_code_topics:
- "dependency-upgrade-policy"
- "file-upload-validation"
- "proxy-trust-boundary"
- "plugin-extension-trust-policy"
primary_source: "https://github.com/vitejs/vite/security/advisories/GHSA-xcj6-pq6g-qj4x"
---
# Vite allows server.fs.deny to be bypassed with .svg or relative paths
## 事件层
- Canonical ID: `vite--CVE-2025-31486`
- 系统: `vite`
- 严重度: `low`
- 来源置信度: `official`
- 官方主源: https://github.com/vitejs/vite/security/advisories/GHSA-xcj6-pq6g-qj4x
- 影响版本: `introduced=6.2.0, fixed<6.2.5, introduced=6.1.0, fixed<6.1.4, introduced=6.0.0, fixed<6.0.14, introduced=5.0.0, fixed<5.4.17, introduced=0, fixed<4.5.12`
- 修复版本: `6.2.5, 6.1.4, 6.0.14, 5.4.17, 4.5.12`
## 其他来源
- https://nvd.nist.gov/vuln/detail/CVE-2025-31486
- https://github.com/vitejs/vite/commit/62d7e81ee189d65899bb65f3263ddbd85247b647
- https://github.com/vitejs/vite
- https://github.com/vitejs/vite/blob/037f801075ec35bb6e52145d659f71a23813c48f/packages/vite/src/node/plugins/asset.ts#L285-L290
## 实验层
- 仅用于自有资产、测试环境或已明确授权目标。
- 允许公网可达目标,但必须满足资产归属或明确授权前提。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 若该案例涉及插件、模块或扩展,应同时检查供应链与升级策略。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
## 修复示例
- [javascript-typescript:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/dependency-upgrade-policy.md)
- [nodejs:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/nodejs/dependency-upgrade-policy.md)
- [java:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/java/dependency-upgrade-policy.md)
- [php:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/php/dependency-upgrade-policy.md)
- [python:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/python/dependency-upgrade-policy.md)
- [ruby:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/ruby/dependency-upgrade-policy.md)
- [csharp:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/csharp/dependency-upgrade-policy.md)
- [go:dependency-upgrade-policy](/Users/x/websafe/05-defense/secure-code/go/dependency-upgrade-policy.md)
- [javascript-typescript:file-upload-validation](/Users/x/websafe/05-defense/secure-code/javascript-typescript/file-upload-validation.md)
- [nodejs:file-upload-validation](/Users/x/websafe/05-defense/secure-code/nodejs/file-upload-validation.md)
- [java:file-upload-validation](/Users/x/websafe/05-defense/secure-code/java/file-upload-validation.md)
- [php:file-upload-validation](/Users/x/websafe/05-defense/secure-code/php/file-upload-validation.md)
- [python:file-upload-validation](/Users/x/websafe/05-defense/secure-code/python/file-upload-validation.md)
- [ruby:file-upload-validation](/Users/x/websafe/05-defense/secure-code/ruby/file-upload-validation.md)
- [csharp:file-upload-validation](/Users/x/websafe/05-defense/secure-code/csharp/file-upload-validation.md)
- [go:file-upload-validation](/Users/x/websafe/05-defense/secure-code/go/file-upload-validation.md)
- [javascript-typescript:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/javascript-typescript/proxy-trust-boundary.md)
- [nodejs:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/nodejs/proxy-trust-boundary.md)
- [java:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/java/proxy-trust-boundary.md)
- [php:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/php/proxy-trust-boundary.md)
- [python:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/python/proxy-trust-boundary.md)
- [ruby:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/ruby/proxy-trust-boundary.md)
- [csharp:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/csharp/proxy-trust-boundary.md)
- [go:proxy-trust-boundary](/Users/x/websafe/05-defense/secure-code/go/proxy-trust-boundary.md)
- [javascript-typescript:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/javascript-typescript/plugin-extension-trust-policy.md)
- [nodejs:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/nodejs/plugin-extension-trust-policy.md)
- [java:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/java/plugin-extension-trust-policy.md)
- [php:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/php/plugin-extension-trust-policy.md)
- [python:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/python/plugin-extension-trust-policy.md)
- [ruby:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/ruby/plugin-extension-trust-policy.md)
- [csharp:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/csharp/plugin-extension-trust-policy.md)
- [go:plugin-extension-trust-policy](/Users/x/websafe/05-defense/secure-code/go/plugin-extension-trust-policy.md)

某些文件未显示,因为此 diff 中更改的文件太多 显示更多