首页 > 专栏 > PHP Bugs PHP Bugs 共 250 条资讯 Weblate: SSRF via URL Parser Differential in `normalize_request_url` (wlc) 2026-06-27 16:20:01 curl: CVE-2026-80256: wcurl backslash bypass 2026-06-27 16:20:01 curl: 06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses 2026-06-27 16:20:01 curl: 41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body 2026-06-27 16:20:01 curl: 33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231) 2026-06-27 16:20:01 curl: 18: Explicit IPv6 proxy zone ID silently ignored — proxy credentials sent to wrong interface 2026-06-27 16:20:01 Nextcloud: Valid share tokens allow to access tempory upload files of share owner 2026-06-27 16:20:01 Weblate: **Unauthenticated IDOR allows modification of payment customer billing information** 2026-06-27 16:20:01 curl: Stacked --proto modifiers leave denied protocol enabled 2026-06-27 16:20:01 curl: --etag-save - truncates append-redirected stdout 2026-06-27 16:20:01 curl: 34: `curl_mprintf` reads `double` for documented `long double` conversions — uninitialized value disclosure 2026-06-27 16:20:01 curl: 28: HTTP/3 UDP path ignores CURL_SOCKOPT_ALREADY_CONNECTED, reconnects callback-provided socket 2026-06-27 16:20:01 curl: 46: `--libcurl` output carries `--insecure` across `--next` boundaries 2026-06-27 16:20:01 Node.js: HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion 2026-06-27 16:20:01 Node.js: Re-entrant `nghttp2_session_mem_send()` during `nghttp2_session_mem_recv()` causes heap-use-after-free in Node.js HTTP/2 2026-06-27 16:20:01 Node.js: node:sqlite SQLTagStore Iterator Replay Lets Attacker Re-Execute Victim-Bound Writes Indefinitely 2026-06-27 16:20:01 Node.js: dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records 2026-06-27 16:20:01 Node.js: Reachable assertion in node:zlib sync API crashes the entire process via spoofed TypedArray byteLength (all 11 *Sync functions affected) 2026-06-27 16:20:01 Node.js: HTTP Request Smuggling via Silent Header Truncation in Node.js HTTP Parser 2026-06-27 16:20:01 WordPress: Author → stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()` 2026-06-27 16:20:01 « 上一页1…45678…13下一页 » 相关分类 P #!/slash/note #UNTAG (B)(F)uzzing on my world (Hi)story (IN)SECURE Magazine Notification (gdb) break *0x972 - 带鱼博客 BeltfishBlog - ./kwaa.dev .NET Blog .Trash /home/rook1e 00's Adventure 0kami's Blog 0x41414141 in ?? () 0x7f Blog 0xRick Owned Root ! 0xd00's blog 1 Byte 1A23 Blog 1A23 Studio 1Link.Fun 1stwebdesigner 251 2BAB 的工程博客 2ch中文网 360 CERT 360 Netlab Blog - Network Securi 38号车评中心 3o米的微博