ADVISORYHIGH8d ago · Sep 8, 2026

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

NLTK users are exposed when its XML parsers process crafted documents.

Several XML parsing sites in NLTK still used xml.etree.ElementTree directly, which honours declarations in a document's internal DTD subset. A crafted document a few hundred bytes long can expand to megabytes in memory (each nesting level multiplies by…

Read it at nltk

More advisory

4 itemsEverything on the wire ›
ADVISORY
CRITICAL: esphome-device-builder — ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
The dashboard reads its authentication credentials from $ESPHOMEUSERNAME and $ESPHOMEPASSWORD. Earlier versions, and the legacy esphome dashboard, read the bare $USERNAME and $PASSWORD instead. When the env vars were renamed the bare names were…
esphome-device-builder
2d
ADVISORY
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
Mockoon's admin API (commons-server/src/libs/server/admin-api.ts) is mounted on the same Express listener as the user-defined mock routes, enabled by default in every shipped runtime (commons-server, CLI, serverless), serves…
@mockoon/commons-server
5d
ADVISORY
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
There is a high-severity request-smuggling vulnerability in Traefik's handling of the HTTP/1.1 Upgrade mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated Upgrade: h2c request header and its…
github.com/traefik/traefik/v3
6d
ADVISORY
Traefik HTTP/3 Backend NTLM Connection Reuse
Traefik's HTTP/3 request path did not initialize the connection-scoped backend transport holder that isolates connection-bound NTLM and Negotiate (Kerberos) authentication on the HTTP/1.1 and HTTP/2 paths. The HTTP/3 entrypoint reuses the HTTPS…
github.com/traefik/traefik/v3
6d