Hsiaoming Yang
14 exploits
Active since Dec 2017
Mistune: XSS via unescaped figclass/figwidth in Figure directive
CVSS 6.1
joserfc 1.3.3-1.3.4 and 1.4.0-1.4.1 - Denial of Service via Large JWT Payload
CVSS 7.5
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVSS 7.5
Authlib JWS JWK Header Injection: Signature Verification Bypass
CVSS 9.1
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVSS 6.5
Authlib 1.6.5-1.6.6 - Improper Verification of Cryptographic Signature
CVSS 9.8
joserfc < 1.6.3 - Unauthenticated Denial of Service via PBES2 Count Parameter
CVSS 7.5
mistune < 0.8.1 - Cross-Site Scripting via _keyify Function
CVSS 6.1
mistune < 2.0.2 - Inefficient Regular Expression Complexity
CVSS 7.5
Authlib < 1.6.4 - Insufficient Verification of Data Authenticity via Critical Header Parameter Bypass
CVSS 7.5
Authlib < 1.6.5 - Uncontrolled Resource Consumption via Oversized JWS/JWT Segments
CVSS 7.5
Authlib < 1.6.5 - Denial of Service via Unbounded DEFLATE Decompression in JWE zip=DEF
CVSS 6.5
joserfc 1.3.3-1.3.4 and 1.4.0-1.4.1 - Denial of Service via Large JWT Payload
CVSS 7.5
Authlib 1.0.0-1.6.5 - Cross-Site Request Forgery via Cache-Backed State Storage
CVSS 5.7