VYPR

uncurl

by chrisd1100

CVEs (1)

  • CVE-2018-6651Feb 5, 2018
    risk 0.00cvss epss 0.00

    In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In…