From acee2705238773af6eb19f158ea698954d79dc6f Mon Sep 17 00:00:00 2001 From: BrewTestBot <1589480+BrewTestBot@users.noreply.github.com> Date: Thu, 3 Sep 2026 10:39:27 +0000 Subject: [PATCH] Matched advisory candidates (shard 39) Base: b378199ecef8d3d83f0770506f963bd7360c79d5 --- advisories/BREW-livereload-CVE-2012-2374.json | 12 +-- advisories/BREW-livereload-CVE-2014-9720.json | 12 +-- .../BREW-livereload-CVE-2023-28370.json | 12 +-- .../BREW-livereload-CVE-2024-52804.json | 12 +-- .../BREW-livereload-CVE-2025-47287.json | 12 +-- .../BREW-livereload-CVE-2025-67724.json | 12 +-- .../BREW-livereload-CVE-2025-67725.json | 12 +-- .../BREW-livereload-CVE-2025-67726.json | 12 +-- .../BREW-livereload-CVE-2026-31958.json | 12 +-- .../BREW-livereload-CVE-2026-35536.json | 16 ++-- .../BREW-livereload-CVE-2026-49853.json | 12 +-- .../BREW-livereload-CVE-2026-49854.json | 12 +-- .../BREW-livereload-CVE-2026-49855.json | 12 +-- .../BREW-livereload-CVE-2026-82397.json | 88 +++++++++++++++++++ .../BREW-livereload-GHSA-753j-mpmx-qq6g.json | 8 +- .../BREW-livereload-GHSA-8423-8fgw-73vq.json | 15 ++-- .../BREW-livereload-GHSA-pw6j-qg29-8w7f.json | 8 +- .../BREW-livereload-GHSA-qppv-j76h-2rpx.json | 8 +- .../BREW-livereload-GHSA-w235-7p84-xx57.json | 8 +- .../BREW-livereload-GHSA-wwv5-g3v4-889x.json | 15 ++-- advisories/BREW-pdfalyzer-CVE-2026-82398.json | 85 ++++++++++++++++++ 21 files changed, 287 insertions(+), 108 deletions(-) create mode 100644 advisories/BREW-livereload-CVE-2026-82397.json create mode 100644 advisories/BREW-pdfalyzer-CVE-2026-82398.json diff --git a/advisories/BREW-livereload-CVE-2012-2374.json b/advisories/BREW-livereload-CVE-2012-2374.json index f32b4789b44..f935fd8835a 100644 --- a/advisories/BREW-livereload-CVE-2012-2374.json +++ b/advisories/BREW-livereload-CVE-2012-2374.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2012-2374", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-f7fv-v9rh-prvc", "CVE-2012-2374", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "2.2.1", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2014-9720.json b/advisories/BREW-livereload-CVE-2014-9720.json index a5371d211ce..666b556bae7 100644 --- a/advisories/BREW-livereload-CVE-2014-9720.json +++ b/advisories/BREW-livereload-CVE-2014-9720.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2014-9720", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-8vpw-mgpf-mpvv", "CVE-2014-9720", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "3.2.2", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2023-28370.json b/advisories/BREW-livereload-CVE-2023-28370.json index 686fd0712d4..1a1daeca3be 100644 --- a/advisories/BREW-livereload-CVE-2023-28370.json +++ b/advisories/BREW-livereload-CVE-2023-28370.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2023-28370", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-hj3f-6gcp-jg8j", "CVE-2023-28370", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.3.2", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2024-52804.json b/advisories/BREW-livereload-CVE-2024-52804.json index e6fa2c5ebe1..46a1ad3ff42 100644 --- a/advisories/BREW-livereload-CVE-2024-52804.json +++ b/advisories/BREW-livereload-CVE-2024-52804.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2024-52804", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-8w49-h785-mj3c", "CVE-2024-52804", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.4.2", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2025-47287.json b/advisories/BREW-livereload-CVE-2025-47287.json index fffa6e8748d..2a8842f099c 100644 --- a/advisories/BREW-livereload-CVE-2025-47287.json +++ b/advisories/BREW-livereload-CVE-2025-47287.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2025-47287", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:20:08Z", "upstream": [ "GHSA-7cx3-6m66-7c5m", "CVE-2025-47287", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2025-67724.json b/advisories/BREW-livereload-CVE-2025-67724.json index 86248ee767f..2187935e170 100644 --- a/advisories/BREW-livereload-CVE-2025-67724.json +++ b/advisories/BREW-livereload-CVE-2025-67724.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2025-67724", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-pr2v-jx2c-wg9f", "CVE-2025-67724", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2025-67725.json b/advisories/BREW-livereload-CVE-2025-67725.json index 14a2124837e..d7ebe07b9fb 100644 --- a/advisories/BREW-livereload-CVE-2025-67725.json +++ b/advisories/BREW-livereload-CVE-2025-67725.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2025-67725", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-c98p-7wgm-6p64", "CVE-2025-67725", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2025-67726.json b/advisories/BREW-livereload-CVE-2025-67726.json index 9bd0412cc98..65f55f74aab 100644 --- a/advisories/BREW-livereload-CVE-2025-67726.json +++ b/advisories/BREW-livereload-CVE-2025-67726.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2025-67726", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-jhmp-mqwm-3gq8", "CVE-2025-67726", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2026-31958.json b/advisories/BREW-livereload-CVE-2026-31958.json index 4219fce6cd7..7a0b0a9ee53 100644 --- a/advisories/BREW-livereload-CVE-2026-31958.json +++ b/advisories/BREW-livereload-CVE-2026-31958.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2026-31958", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-qjxf-f2mg-c6mc", "CVE-2026-31958", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.5", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2026-35536.json b/advisories/BREW-livereload-CVE-2026-35536.json index 0be5c803918..dce4b62f565 100644 --- a/advisories/BREW-livereload-CVE-2026-35536.json +++ b/advisories/BREW-livereload-CVE-2026-35536.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2026-35536", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:20:08Z", "upstream": [ "GHSA-78cv-mqj4-43f7", "CVE-2026-35536", @@ -34,7 +34,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.5", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -47,24 +47,24 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2026-49853.json b/advisories/BREW-livereload-CVE-2026-49853.json index 7cd9e23eb01..135a573f26d 100644 --- a/advisories/BREW-livereload-CVE-2026-49853.json +++ b/advisories/BREW-livereload-CVE-2026-49853.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2026-49853", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:20:08Z", "upstream": [ "GHSA-3x9g-8vmp-wqvf", "CVE-2026-49853", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.6", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2026-49854.json b/advisories/BREW-livereload-CVE-2026-49854.json index 3fc9c2c18e1..067e88ed842 100644 --- a/advisories/BREW-livereload-CVE-2026-49854.json +++ b/advisories/BREW-livereload-CVE-2026-49854.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2026-49854", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-cx3h-4qpv-8hc9", "CVE-2026-49854", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.6", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2026-49855.json b/advisories/BREW-livereload-CVE-2026-49855.json index d630d34d477..2bf074e5348 100644 --- a/advisories/BREW-livereload-CVE-2026-49855.json +++ b/advisories/BREW-livereload-CVE-2026-49855.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-CVE-2026-49855", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-mgf9-4vpg-hj56", "CVE-2026-49855", @@ -33,7 +33,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.6", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -46,16 +46,16 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" }, { "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-CVE-2026-82397.json b/advisories/BREW-livereload-CVE-2026-82397.json new file mode 100644 index 00000000000..9e769e11191 --- /dev/null +++ b/advisories/BREW-livereload-CVE-2026-82397.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-livereload-CVE-2026-82397", + "published": "2026-09-03T09:21:24Z", + "modified": "2026-09-03T09:21:24Z", + "upstream": [ + "GHSA-mpf4-983q-p7j4", + "CVE-2026-82397" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "livereload", + "purl": "pkg:brew/livereload" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.7.1_3" + } + ] + } + ], + "ecosystem_specific": { + "fix": "bump", + "range_state": "fixed", + "upstream_fixed_in": "6.5.8", + "resource": "tornado", + "resource_purl": "pkg:pypi/tornado@6.5.8" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "tornado", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", + "resource": "tornado" + } + ] + }, + "summary": " Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop", + "details": "## Summary\n\nTornado parses `application/x-www-form-urlencoded` bodies with `urllib.parse.parse_qs` and does not pass `max_num_fields`. A body made almost entirely of separators produces tens of millions of fields, and the parse happens on the event loop before the handler runs, so a single request stalls the whole server.\n\n## Where it is\n\n`tornado/escape.py`, at HEAD `e530031405e2154654dedc4c84d5656b557ea310`:\n\n```python\nresult = urllib.parse.parse_qs(\n qs, keep_blank_values, strict_parsing, encoding=\"latin1\", errors=\"strict\"\n)\n```\n\n`max_num_fields` is the parameter CPython added for exactly this, and it is absent.\n\nThe path to it is entirely server-side and pre-dispatch. `RequestHandler._execute` parses the body at `tornado/web.py:1821`, which reaches `HTTPServerRequest._parse_body` at `tornado/httputil.py:636`, and the urlencoded branch of `parse_body_arguments` calls `parse_qs_bytes` at `tornado/httputil.py:1030`.\n\nThe size that reaches it is bounded only by the body cap, which defaults to the stream's `max_buffer_size` of 104857600 at `tornado/iostream.py:239`, applied as the request body default at `tornado/http1connection.py:136-140`. A 100 MB body of separators is around fifty million fields.\n\n## Impact\n\nDenial of service against the whole process, not one request. Tornado is single-threaded and the parse is synchronous on the event loop, so every other connection waits. No authentication is needed if any route accepts a form post, which is the normal case.\n\n## Suggested fix\n\nPass a bound:\n\n```python\nresult = urllib.parse.parse_qs(\n qs, keep_blank_values, strict_parsing, encoding=\"latin1\", errors=\"strict\",\n max_num_fields=max_num_fields,\n)\n```\n\nwith a conservative default and a way for applications to raise it. CPython raises `ValueError` when the limit is exceeded, which maps cleanly onto a 400.\n\nLowering the default body cap for urlencoded specifically would help too, since 100 MB of form fields is not a shape any real client sends.\n\n## Why I do not think this is a duplicate\n\nThe published tornado advisories cover out-of-bounds access in the C extension, unbounded accumulation of decompressed chunks in `AsyncHTTPClient`, the Authorization header surviving cross-origin redirects, credential leakage on curl handle reuse, and cookie attribute validation. The decompression one is the nearest in spirit and is on the client side; this is the server parsing a request body. The call is unchanged at HEAD.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-mpf4-983q-p7j4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82397" + }, + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/pull/3704" + }, + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de" + }, + { + "type": "PACKAGE", + "url": "https://github.com/tornadoweb/tornado" + }, + { + "type": "WEB", + "url": "https://github.com/tornadoweb/tornado/releases/tag/v6.5.8" + } + ] +} diff --git a/advisories/BREW-livereload-GHSA-753j-mpmx-qq6g.json b/advisories/BREW-livereload-GHSA-753j-mpmx-qq6g.json index 2588d72e28d..add84f058a3 100644 --- a/advisories/BREW-livereload-GHSA-753j-mpmx-qq6g.json +++ b/advisories/BREW-livereload-GHSA-753j-mpmx-qq6g.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-GHSA-753j-mpmx-qq6g", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:20:08Z", "upstream": [ "GHSA-753j-mpmx-qq6g" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.4.1", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-GHSA-8423-8fgw-73vq.json b/advisories/BREW-livereload-GHSA-8423-8fgw-73vq.json index 864ec66b219..3bfefa05683 100644 --- a/advisories/BREW-livereload-GHSA-8423-8fgw-73vq.json +++ b/advisories/BREW-livereload-GHSA-8423-8fgw-73vq.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-GHSA-8423-8fgw-73vq", "published": "2026-09-02T09:14:08Z", - "modified": "2026-09-02T09:14:08Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-8423-8fgw-73vq" ], @@ -19,16 +19,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.7.1_3" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "6.5.8", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -41,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-GHSA-pw6j-qg29-8w7f.json b/advisories/BREW-livereload-GHSA-pw6j-qg29-8w7f.json index 6b82036b7f3..e183f067a6a 100644 --- a/advisories/BREW-livereload-GHSA-pw6j-qg29-8w7f.json +++ b/advisories/BREW-livereload-GHSA-pw6j-qg29-8w7f.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-GHSA-pw6j-qg29-8w7f", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-pw6j-qg29-8w7f" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.5.7", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-GHSA-qppv-j76h-2rpx.json b/advisories/BREW-livereload-GHSA-qppv-j76h-2rpx.json index 8a9d0436f39..3e9ff2124ae 100644 --- a/advisories/BREW-livereload-GHSA-qppv-j76h-2rpx.json +++ b/advisories/BREW-livereload-GHSA-qppv-j76h-2rpx.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-GHSA-qppv-j76h-2rpx", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-qppv-j76h-2rpx" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.3.3", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-GHSA-w235-7p84-xx57.json b/advisories/BREW-livereload-GHSA-w235-7p84-xx57.json index d6246b17a4a..c5e995016d5 100644 --- a/advisories/BREW-livereload-GHSA-w235-7p84-xx57.json +++ b/advisories/BREW-livereload-GHSA-w235-7p84-xx57.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-GHSA-w235-7p84-xx57", "published": "2026-08-13T17:02:57Z", - "modified": "2026-08-13T17:02:57Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-w235-7p84-xx57" ], @@ -31,7 +31,7 @@ "range_state": "fixed", "upstream_fixed_in": "6.4.1", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -44,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-livereload-GHSA-wwv5-g3v4-889x.json b/advisories/BREW-livereload-GHSA-wwv5-g3v4-889x.json index 035667d9f50..3a3737a3aae 100644 --- a/advisories/BREW-livereload-GHSA-wwv5-g3v4-889x.json +++ b/advisories/BREW-livereload-GHSA-wwv5-g3v4-889x.json @@ -2,7 +2,7 @@ "schema_version": "1.7.3", "id": "BREW-livereload-GHSA-wwv5-g3v4-889x", "published": "2026-09-02T09:14:08Z", - "modified": "2026-09-02T09:14:08Z", + "modified": "2026-09-03T09:21:24Z", "upstream": [ "GHSA-wwv5-g3v4-889x" ], @@ -19,16 +19,19 @@ "events": [ { "introduced": "0" + }, + { + "fixed": "2.7.1_3" } ] } ], "ecosystem_specific": { - "fix": null, - "range_state": "affected", + "fix": "bump", + "range_state": "fixed", "upstream_fixed_in": "6.5.8", "resource": "tornado", - "resource_purl": "pkg:pypi/tornado@6.5.7" + "resource_purl": "pkg:pypi/tornado@6.5.8" } } ], @@ -41,8 +44,8 @@ "strategy": "registry", "ecosystem": "PyPI", "name": "tornado", - "subject_version": "6.5.7", - "key": "pkg:pypi/tornado@6.5.7", + "subject_version": "6.5.8", + "key": "pkg:pypi/tornado@6.5.8", "resource": "tornado" } ] diff --git a/advisories/BREW-pdfalyzer-CVE-2026-82398.json b/advisories/BREW-pdfalyzer-CVE-2026-82398.json new file mode 100644 index 00000000000..beb46eeeed5 --- /dev/null +++ b/advisories/BREW-pdfalyzer-CVE-2026-82398.json @@ -0,0 +1,85 @@ +{ + "schema_version": "1.7.3", + "id": "BREW-pdfalyzer-CVE-2026-82398", + "published": "2026-09-03T09:45:27Z", + "modified": "2026-09-03T09:45:27Z", + "upstream": [ + "GHSA-fc8x-2rww-xw9m", + "CVE-2026-82398" + ], + "affected": [ + { + "package": { + "ecosystem": "Homebrew", + "name": "pdfalyzer", + "purl": "pkg:brew/pdfalyzer" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "fix": null, + "range_state": "affected", + "upstream_fixed_in": "6.15.0", + "resource": "pypdf", + "resource_purl": "pkg:pypi/pypdf@6.6.0" + } + } + ], + "database_specific": { + "source": "matched", + "strategy": "registry", + "confidence": "high", + "upstream_evidence": [ + { + "strategy": "registry", + "ecosystem": "PyPI", + "name": "pypdf", + "subject_version": "6.6.0", + "key": "pkg:pypi/pypdf@6.6.0", + "resource": "pypdf" + } + ] + }, + "summary": "pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace", + "details": "### Impact\nAn attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a call to `read_until_whitespace` with an input which does not have whitespace for a long time.\n\n### Patches\nThis has been fixed in [pypdf==6.15.0](https://github.com/py-pdf/pypdf/releases/tag/6.15.0).\n\n### Workarounds\nIf you cannot upgrade yet, consider applying the changes from PR [#3947](https://github.com/py-pdf/pypdf/pull/3947).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82398" + }, + { + "type": "WEB", + "url": "https://github.com/py-pdf/pypdf/pull/3947" + }, + { + "type": "WEB", + "url": "https://github.com/py-pdf/pypdf/commit/4959848e057e37c218dccad7465259210923faaa" + }, + { + "type": "PACKAGE", + "url": "https://github.com/py-pdf/pypdf" + }, + { + "type": "WEB", + "url": "https://github.com/py-pdf/pypdf/releases/tag/6.15.0" + } + ] +}