Medium severity5.4NVD Advisory· Published Mar 19, 2023· Updated Jun 17, 2026
CVE-2023-1496
CVE-2023-1496
Description
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/imgproxy/imgproxy/v3Go | < 3.14.0 | 3.14.0 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/imgproxy/imgproxy/commit/62f8d08a93d301285dcd1dabcc7ba10c6c65b689nvdPatchWEB
- huntr.dev/bounties/de603972-935a-401a-96fb-17ddadd282b2nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-ch9g-x9j7-rcgpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-1496ghsaADVISORY
News mentions
0No linked articles in our index yet.