---
title: 'Topic: severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
canonical_url: https://portal.chinng-lab-srv.dev/topics/severity-cvss-3-1-av-n-ac-l-pr-n-ui-n-s-u-c-h-i-n-a-n.md
content_kind: topic
updated_at: '2026-08-02T07:21:57Z'
---

# Topic: severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/severity-cvss-3-1-av-n-ac-l-pr-n-ui-n-s-u-c-h-i-n-a-n.md
- Last updated: 2026-08-02T07:21:57Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=severity%3ACVSS%3A3.1%2FAV%3AN%2FAC%3AL%2FPR%3AN%2FUI%3AN%2FS%3AU%2FC%3AH%2FI%3AN%2FA%3AN
- MCP: portal_search(q="severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N")

## Related categories

- security/library
- security/os

## Related entities

- GitPython
- Latvia
- ElectricVehicle
- PyPI
- Aviation Wire
- Starlette
- AND CaaaLL
- CVE-2013-0074
- GitHub
- XSMB
- ConnectionPooler
- Default Merkel

## Latest articles

- [GHSA-94p4-4cq8-9g67: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)](https://portal.chinng-lab-srv.dev/security/library/security-20260725-df0150.md): GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
- [CVE-2026-67322: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL](https://portal.chinng-lab-srv.dev/security/library/security-20260722-bdbe76.md): GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
- [CVE-2026-48818 — starlette](https://portal.chinng-lab-srv.dev/security/library/security-20260714-163dc6.md): Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to…
- [CVE-2026-48818: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows](https://portal.chinng-lab-srv.dev/security/library/security-20260711-8dd28c.md): Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- [DEBIAN-CVE-2026-45445 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f5242e.md): Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summ…
- [CVE-2026-47265 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-ce4cf5.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin r…
- [CVE-2026-5773: wrong reuse of SMB connection](https://portal.chinng-lab-srv.dev/security/library/security-20260708-c317fd.md): wrong reuse of SMB connection
- [CVE-2026-41066 — lxml](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d6cb41.md): lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML in…
- [CVE-2026-41066: lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a46103.md): lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
- [DEBIAN-CVE-2026-31790 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-a6be1d.md): Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitiali…
- [CVE-2026-34515 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-9ce7c4.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This…
- [DEBIAN-CVE-2023-5363 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-490383.md): Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric…
