Total vulnerabilities in the database
In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.
Software | From | Fixed in |
---|---|---|
nim-lang / nim | - | 1.2.6.x |