Malformed RSA JWK Aborts Parsing of an Entire JWK Set
PyJWT
A malformed RSA JWK inside a JWK Set aborts parsing of the entire set instead of being skipped, so one bad key can block every valid key in a fetched JWKS from loading.
Every zero-day we find becomes developer security training. Your team trains on SecDim's latest discoveries as soon as we publish them.
PyJWT
A malformed RSA JWK inside a JWK Set aborts parsing of the entire set instead of being skipped, so one bad key can block every valid key in a fetched JWKS from loading.
ONNX
An ineffective symlink check in ONNX's model checker follows a symlink to an arbitrary location, letting a malicious model read files outside the model or user-provided directory. The third recurrence of this vulnerability class, following two earlier incomplete fixes.
picklescan
A bypass in picklescan, the pickle-file scanner platforms like Hugging Face use to gate malicious ML model uploads, that lets an attacker exfiltrate sensitive data via DNS at model load time even after the file passes scanning.
Every disclosure on this page is a new vulnerability in open source code. SecDim turns it into developer security training for your own engineering team.