nim-lang
OSS Librariesoss-project
Top products
Latest CVEs
The 11 most recently published vulnerabilities affecting nim-lang.
- CVE-2021-46872An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some a...6.1
- CVE-2022-23602Nim's rst parser sandboxed mode allows include which can embed any local file7.7
- CVE-2020-23171A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the cra...5.5
- CVE-2021-29495Nim stdlib httpClient does not validate peer certificates by default5.9
- CVE-2021-21373Nimble falls back to insecure http url when fetching packages7.5
- CVE-2021-21374Nimble fails to validate certificates due to insecure httpClient defaults8.1
- CVE-2021-21372Nimble arbitrary code execution for specially crafted package metadata8.3
- CVE-2020-15690In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.9.8
- CVE-2020-15694In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a...7.5
- CVE-2020-15693In Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF injection in the target URL. An injection is possible if the attacker controls any part of the URL provided in a call (such as...6.5
- CVE-2020-15692In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attack...9.8