Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-5hw4-m7f3-hhx8: TCPDF vulnerable to attackers triggering deserialization of arbitrary data

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

ghsa
#git#pdf

TCPDF vulnerable to attackers triggering deserialization of arbitrary data

Critical severity GitHub Reviewed Published Oct 6, 2022 • Updated Oct 6, 2022

ghsa: Latest News

GHSA-3qhf-m339-9g5v: MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS