Tomas Della Vedova

2 exploits Active since Nov 2020
CVE-2020-7764 WRITEUP MEDIUM WRITEUP
find-my-way <2.2.5 & 3.0.0-3.0.5 - DoS
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack.
CVSS 5.9
CVE-2022-39288 WRITEUP HIGH WRITEUP
fastify < 4.8.1 - Denial of Service via Malicious Content-Type Header
fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause the application to crash. This issue has been addressed in commit `fbb07e8d` and will be included in release version 4.8.1. Users are advised to upgrade. Users unable to upgrade may manually filter out http content with malicious Content-Type headers.
CVSS 7.5