CVE-2024-45590 - Denial of Service Vulnerability in body-parser <1.20.3 for Node.js
If you work with Node.js, you’ve probably used body-parser before as part of your web server. But, a recent vulnerability has been
CVE-2024-43799 - Critical RCE in Send Library Can Turn File Streaming into Server Exploit
On May 22, 2024, a critical remote code execution (RCE) vulnerability was disclosed in Send, a popular Node.js library used for streaming files over
CVE-2024-7341 - Exploiting Session Fixation in Keycloak SAML Adapters – A Deep Dive
In early 2024, CVE-2024-7341 was disclosed, uncovering a session fixation vulnerability in SAML adapters for Keycloak, the widely used open-source identity and
CVE-2024-45296 - How A Regex Bug in path-to-regexp Can Freeze Your JavaScript App
When we build Express, Koa, or other Node.js web apps, one behind-the-scenes library you’ll often find is path-to-regexp. It
CVE-2024-45411 - How Twig's Sandbox Flaw let Hackers Slip Through (with Code, Exploit, and Fix Details)
Twig is one of the most popular template engines for PHP. It helps make website templates safe and simple—especially when users can contribute their
Episode
00:00:00
00:00:00