Showing 2 vulnerabilities on this page for github.com/imgproxy/imgproxy/v3

Signals CISA KEV Ransomware Nuclei
Go vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

imgproxy is vulnerable to Server-Side Request Forgery

imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.

CWE-918May 8, 20231 related artifact
CVSS5.3v3.1EPSS2.21%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cross-site Scripting (XSS) - Reflected in imgproxy/imgproxy

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

CWE-79Mar 19, 20231 related artifact
CVSS5.4v3.1EPSS1.59%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX