← Zurück zur CVE-Suche

CVE-2026-50288

SpecifyJS

Beschreibung

SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl` function returned without throwing, silently allowing the request to proceed without HTTPS validation. Starting in version 0.2.136, the catch block now throws an error instead of silently returning.

CVSS 8.7EPSS 0.27599999999999997%Risiko 0.89
Quelle öffnen
Veröffentlicht
2026-08-21 20:16:36
Betroffene Versionen
<0.2.136
Typ
Bibliothek
Zuletzt geändert
2026-08-21 20:16:36
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X