---
title: 'Topic: severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
canonical_url: https://portal.chinng-lab-srv.dev/topics/severity-cvss-3-1-av-n-ac-l-pr-n-ui-n-s-u-c-n-i-n-a-h.md
content_kind: topic
updated_at: '2026-07-24T07:02:21Z'
---

# Topic: severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/severity-cvss-3-1-av-n-ac-l-pr-n-ui-n-s-u-c-n-i-n-a-h.md
- Last updated: 2026-07-24T07:02:21Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=severity%3ACVSS%3A3.1%2FAV%3AN%2FAC%3AL%2FPR%3AN%2FUI%3AN%2FS%3AU%2FC%3AN%2FI%3AN%2FA%3AH
- MCP: portal_search(q="severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H")

## Related categories

- security/library
- security/os

## Related entities

- CVE-2026-44243
- Ter Haibin Airport Bombing<br
- HigherDose
- write-capable token
- OpenAI
- wiki_upload
- Pillow
- JSON-LD
- two-dose treatment
- VIATRIX
- Forbes JAPAN
- Python
- CVE-2013-0074
- GitHub
- customer
- ghost
- Monaco bomb suspect
- HashTag
- Link Header

## Latest articles

- [CVE-2026-59200: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()](https://portal.chinng-lab-srv.dev/security/library/security-20260724-bc2416.md): Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
- [CVE-2026-59205: Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch](https://portal.chinng-lab-srv.dev/security/library/security-20260721-9c81bc.md): Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
- [CVE-2026-59200: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()](https://portal.chinng-lab-srv.dev/security/library/security-20260721-3aa418.md): Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
- [CVE-2026-59199: Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow](https://portal.chinng-lab-srv.dev/security/library/security-20260721-ca974b.md): Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
- [CVE-2026-55380: Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-4fa7c9.md): Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
- [CVE-2026-55379: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading](https://portal.chinng-lab-srv.dev/security/library/security-20260721-d74706.md): Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
- [CVE-2026-54060: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-a1dd3d.md): Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
- [CVE-2026-54059: Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading](https://portal.chinng-lab-srv.dev/security/library/security-20260721-f6d04d.md): Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
- [CVE-2026-59203 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-a3f93e.md): Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file…
- [CVE-2026-59205 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-51776c.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image wh…
- [CVE-2026-59199 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-ec2875.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in…
- [GHSA-xf7x-x43h-rpqh: json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS](https://portal.chinng-lab-srv.dev/security/library/security-20260714-fc7931.md): json_repair: Circular JSON Schema `$ref` causes unbounded CPU DoS
- [CVE-2025-62727: Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``](https://portal.chinng-lab-srv.dev/security/library/security-20260711-dc1ff3.md): Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
- [CVE-2026-55379 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-f7ab82.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() wi…
- [CVE-2026-55380 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-cb6737.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompres…
- [CVE-2026-54060 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-3d7d29.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._de…
- [CVE-2026-54059 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-27b2a1.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without callin…
- [CVE-2026-54278 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-bacc5b.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chun…
- [CVE-2026-54277 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-b8656e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using…
- [CVE-2026-54280 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-46393e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a pa…
- [CVE-2026-54279 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-1775ac.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() l…
- [CVE-2026-54283 — starlette](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d980d5.md): Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are…
- [CVE-2026-54275 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260711-347a7c.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an applica…
- [CVE-2026-54273 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-e1a21e.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able…
- [CVE-2026-54274 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-cf3c24.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual…
- [CVE-2026-50269 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-ad7e36.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to i…
- [CVE-2026-57585: MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error](https://portal.chinng-lab-srv.dev/security/library/security-20260711-cdb45c.md): MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
- [CVE-2026-54283: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS](https://portal.chinng-lab-srv.dev/security/library/security-20260711-e1d2eb.md): Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
- [DEBIAN-CVE-2026-9076 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f52085.md): Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in…
- [DEBIAN-CVE-2026-42765 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-8ecc35.md): Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a…
- [DEBIAN-CVE-2026-42764 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-02bf21.md): Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer d…
- [DEBIAN-CVE-2026-34183 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-53fc82.md): Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbo…
- [DEBIAN-CVE-2026-34180 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f80dcc.md): Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platfo…
- [CVE-2026-44432 — urllib3](https://portal.chinng-lab-srv.dev/security/library/security-20260711-10a0ef.md): urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) c…
- [CVE-2026-6276: stale custom cookie host causes cookie leak](https://portal.chinng-lab-srv.dev/security/library/security-20260708-ca0560.md): stale custom cookie host causes cookie leak
- [CVE-2026-44432: urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d45cff.md): urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
- [CVE-2026-40192 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-f651a5.md): Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attac…
- [CVE-2026-40192: FITS GZIP decompression bomb in Pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260711-42df7e.md): FITS GZIP decompression bomb in Pillow
- [DEBIAN-CVE-2026-28390 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-7d7a65.md): Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-contro…
- [DEBIAN-CVE-2026-28389 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-556164.md): Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled…
- [DEBIAN-CVE-2026-28388 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-f31bc6.md): Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A N…
- [DEBIAN-CVE-2026-28386 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-0d61a0.md): Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher block…
- [CVE-2026-34516: AIOHTTP has a Multipart Header Size Bypass](https://portal.chinng-lab-srv.dev/security/library/security-20260711-948d77.md): AIOHTTP has a Multipart Header Size Bypass
- [CVE-2026-34513 — aiohttp](https://portal.chinng-lab-srv.dev/security/library/security-20260714-667ec2.md): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situ…
- [DEBIAN-CVE-2025-69420 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-1065f4.md): Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or N…
- [DEBIAN-CVE-2025-69421 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-101bd9.md): Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash…
- [CVE-2025-62727: Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a27c94.md): Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
- [DEBIAN-CVE-2025-9230 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-bd7b52.md): Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger…
- [DEBIAN-CVE-2024-4741 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-0abcd1.md): Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of pote…
- [DEBIAN-CVE-2024-6119 — openssl](https://portal.chinng-lab-srv.dev/security/os/security-20260705-d48d7e.md): Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the…
