Public Disclosures

Vulnerabilities discovered by FuzzingBrain that are fixed or confirmed/accepted upstream and publicly verifiable — every row links to the public report, PR, issue, or advisory.

74 findings across 31 projects  ·  fixed 67   confirmed 7

#ProjectVulnerabilityTypeSeverityStatusPublic report
1auth0-spa-jsWorker retains refresh tokens after logout() — silent token re-mint post-logoutinsufficient-session-expiration / use-after-release (CWE-613, CWE-672)highfixedGitHub issue ↗
2avroDecompression bomb causes OutOfMemoryError via unbounded codec decompressionDecompression Bomb (CWE-409)highfixedGitHub PR ↗
3avroNegative block size causes allocation-size-too-big crashUncontrolled Memory Allocation (CWE-789)highfixedGitHub PR ↗
4avroNegative string length causes allocation-size-too-big crashUncontrolled Memory Allocation (CWE-789)highfixedGitHub PR ↗
5binutilsOOM in rust_demangle via unbounded lifetime count in demangle_binderOut-of-Memory / Denial of Service (CWE-400)mediumfixedSourceware ↗
6brotlibrotli CLI CopyStat path-based chmod/chown after fclose() — TOCTOU symlink-followingtoctou-race / symlink-following (CWE-367)highfixedGitHub PR ↗
7chromiumAssertion Failure in aom_rb_read_literal via AV1 Config Parserassertion-failuremediumfixedaomedia.issues.chromium.org issue ↗
8chromiumData race on GrTextureProxy::fProxyProvider — recorder dtor vs direct-context flushdata-racemediumfixedChromium issue ↗
9chromiumDenial of Service via Infinite Recode Loop in libaom AV1 SVC Encoder (encode_with_recode_loop_and_filter → av1_resize_plane)uncontrolled-resource-consumptionmediumfixedChromium issue ↗
10chromiumEmpty-Vector OOB in printing::ParsePpdCapabilities PaperList Default Selection (Browser-Process DoS via Rogue Printer)oob-readmediumfixedChromium issue ↗
11chromiumHeap Buffer Overflow in AV1RateControlRTC via av1_restore_layer_contextheap-buffer-overflowhighfixedChromium issue ↗
12chromiumHeap Buffer Overflow in VP9 Encoder via vpx_codec_enc_config_set When Increasing Resolutionheap-buffer-overflowhighfixedWebM issue ↗
13chromiumHeap Buffer Overflow Read in FriendlyNameMapper::ParseInstruction OpTypePointer Arm via emitAsUnknown Bypassheap-buffer-overflowmediumfixedGitHub issue ↗
14chromiumHeap Buffer Overflow Read in jsoncpp Json::OurReader::getLocationLineAndColumn via CR-LF Look-ahead Past end_heap-buffer-overflowmediumfixedGitHub issue ↗
15chromiumNULL Pointer Dereference in WebPMuxAssemble (muxedit.c)null-pointer-dereferencehighfixedWebM issue ↗
16chromiumOOB Pixel Pointer in Skia Raster8888BlurAlgorithm via eval_blur_passes X→Y Rebind Off-by-One (Release Build Memory Safety)out-of-bounds-accessmediumfixedChromium issue ↗
17chromiumOOB Read in libsharpyuv FixedPointInterpolation via Unclamped High-Bit-Depth Pixel Index into kGammaToLinearTabSoob-readhighfixedWebM issue ↗
18chromiumOut-of-Bounds Read in SharpYuvConvert() via Missing Stride Validationheap-buffer-overflowhighfixedWebM issue ↗
19chromiumPre-Auth DoS in openscreen Cast ANSWER Parser via jsoncpp Non-Object find() Abort (AudioConstraints::TryParse et al.)denial-of-servicemediumfixedChromium issue ↗
20chromiumPre-Auth DoS in openscreen ReceiverMessage::Parse via jsoncpp Non-Object find() Abortdenial-of-servicemediumfixedChromium issue ↗
21chromiumPre-Auth DoS in openscreen SenderMessage::Parse via jsoncpp Non-Object find() Abortdenial-of-servicemediumfixedChromium issue ↗
22chromiumSEGV in spvtools::Disassembler::OrderBlocks via Empty Block Vector after OpFunctionEnd Without OpLabelsegvmediumfixedGitHub issue ↗
23chromiumUnbounded Heap Allocation (~1.6 GB) in HashMgr::load_tables via Unvalidated tablesize Field in .dic Fileunbounded-allocation-dosmediumfixedGitHub issue ↗
24chromiumUndefined Behavior in libvpx VP9 SVC Rate-Control via NaN-to-int Cast in saturate_cast_double_to_int (vp9_update_buffer_level_svc_preencode)undefined-behaviormediumfixedWebM issue ↗
25chromiumUndefined Behavior in libvpx vpx_img_flip via Pointer Arithmetic on NULL planes[VPX_PLANE_ALPHA]undefined-behaviorlowfixedWebM issue ↗
26chromiumUse-After-Free / Null Pointer Dereference in TransliterationRule Destructoruse-after-freehighfixedUnicode Jira ↗
27curlcurl: option credentials leak across https->http same-host redirect (scheme ignored in origin comparison)credential leakage / improper origin comparisonlowfixedGitHub PR ↗
28dtcMisaligned Memory Access in fdt32_to_cpu() During FDT Node Traversalundefined-behavior-misaligned-accessmediumfixedGitHub issue ↗
29FreeRDPPre-Auth Memory Leak in FreeRDP NTLM AuthenticateMessage Parser Failure Pathmemory-leakhighfixedGitHub issue ↗
30fwupdCAB MSZIP Decompression BombDecompression Bomb (CWE-409)mediumfixedGitHub issue ↗
31fwupdInteger Underflow in sbatlevel Section ParserInteger Underflow (CWE-191)mediumfixedGitHub issue ↗
32GhidraOOM in cplus_demangle due to malformed symbolOut-of-Memory / Denial of Service (CWE-400)mediumfixedGitHub advisory ↗
33GhidraOOM in rust_demangle due to nested generic parametersOut-of-Memory / Denial of Service (CWE-400)mediumfixedGitHub advisory ↗
34gooseDeeplink module-state race causes cross-window deep link contaminationrace-conditionhighfixedGitHub issue ↗
35gooseOIDC proxy MAX_TOKEN_AGE_SECONDS bypasses exp check (expired token replay)authentication-bypasshighfixedGitHub issue ↗
36gooseSSRF via fetch-metadata IPC handler to cloud metadata and internal hostsserver-side-request-forgeryhighfixedGitHub issue ↗
37graaljsIllformedLocaleException treated as Internal Error in Intl APIimproper-exception-handlingmediumfixedGitHub issue ↗
38graaljsStringIndexOutOfBoundsException in RegexLexer.consumeChar causes Internal Erroruncaught-exceptionmediumfixedGitHub issue ↗
39harfbuzzOOB Write in HarfBuzz fontations Glyph-Name Callback with size == 0out-of-bounds-writemediumfixedGitHub issue ↗
40icuUse-After-Free / Null Pointer Dereference in TransliterationRule Destructoruse-after-freehighfixedUnicode Jira ↗
41jqNULL Pointer Dereference in dump_operationNULL Pointer Dereference (CWE-476)mediumfixedGitHub issue ↗
42json-javaClassCastException in JSONML.toJSONArray due to unsafe type castType ConfusionmediumfixedGitHub issue ↗
43json-javaNumberFormatException in XMLTokener.unescapeEntity due to missing input validationInput Validation ErrormediumfixedGitHub issue ↗
44json-javaStringIndexOutOfBoundsException in XMLTokener.unescapeEntity due to missing length checkInput Validation ErrormediumfixedGitHub issue ↗
45libavifHeap Buffer Overflow in libavif Android JNI via Signed-Int Length Sign-Extensionheap-buffer-overflowhighfixedGitHub issue ↗
46libheifHeap Buffer Overflow in libheif heif_image_crop (pixelimage.cc)heap-buffer-overflowhighfixedGitHub issue ↗
47mongooseHeap Buffer Overflow in mg_matchHeap Buffer Overflow (CWE-122)mediumfixedGitHub issue ↗
48mongooseHeap Buffer Overflow in mg_match - s.buf[j] access without bounds checkHeap Buffer Overflow (CWE-125 Out-of-bounds Read)mediumfixedGitHub issue ↗
49mongooseHeap Buffer Overflow in mg_mqtt_next_prop - MQTT5 property parsing OOB readHeap Buffer Overflow (CWE-125 Out-of-bounds Read)highfixedGitHub issue ↗
50ndpinDPI Heap OOB Read in ndpi_hex_decode via Unbounded sscanf Over Non-NUL-Terminated Borrowed Buffer (ndpi_decode_tls_blocks)heap-buffer-overflow-readmediumfixedGitHub issue ↗
51net-snmpnet-snmp: heap-use-after-free in smux_rreq_process (SMUX RReq DELETE) dereferences freed handler reginfoheap-use-after-freemediumfixedGitHub issue ↗
52net-snmpNULL Pointer Dereference in vacm_parse_config_groupnull-pointer-dereferencemediumfixedGitHub issue ↗
53opc-uaAssertion Failure in PubSub JSON NetworkMessage Decoderassertion-failuremediumfixedGitHub PR ↗
54opencvHeap buffer overflow in YAML parser parseKey() when key is emptyheap-buffer-overflowlowfixedGitHub issue ↗
55OpenPrint CUPSHeap buffer overflow in cupsUTF8ToCharset when processing truncated UTF-8 sequencesOut-of-bounds Read (CWE-125)highfixedGitHub issue ↗
56OpenPrint CUPSNULL Pointer Dereference in cupsResolveConflicts()NULL Pointer Dereference (CWE-476)highfixedGitHub commit ↗
57OpenPrint CUPSOpen redirect issue in OAuth login flowOpen Redirect (CWE-601)highfixedGitHub issue ↗
58opensslStack Buffer Over-Read in DES OFB/CFB64 via Unchecked num Parameterstack-buffer-overflowlowfixedGitHub issue ↗
59otsNULL Pointer Dereference in OTS ProcessGeneric() with TABLE_ACTION_PASSTHRUnull-pointer-dereferencemediumfixedGitHub issue ↗
60paddlePaddle Download Helpers TAR extraction path traversal / arbitrary file writePath Traversal (CWE-22)highfixedGitHub ↗
61simdutfHeap buffer overflow in convert_utf16_to_utf8_safe due to write-before-check patternHeap Buffer Overflow (CWE-787)highfixedGitHub issue ↗
62systemdAlgorithmic-Complexity DoS in systemd PE/UKI Parser (382-byte PE wedges parser >10s)algorithmic-complexity-doslowfixedGitHub PR ↗
63systemdOut-of-Bounds Reads in sd-hwdb Trie Walker (offset dereferenced before bounds check)out-of-bounds-readhighfixedGitHub PR ↗
64upxHeap Buffer Overflow in UPX PackLinuxElf64::generateElfHdr when packing malformed ELF64 filesHeap Buffer Overflow (CWE-122)highfixedGitHub issue ↗
65upxHeap Buffer Overflow in UPX PeFile::processLoadConf when packing malformed PE32 filesHeap Buffer Overflow (CWE-122)criticalfixedGitHub issue ↗
66upxMemory Leak in UPX PackLinuxElf32::pack2 when packing ELF executablesMemory Leak (CWE-401)mediumfixedGitHub issue ↗
67upxMemory Leak in UPX PeFile::Resource::convert() when processing PE resourcesMemory Leak (CWE-401)lowfixedGitHub issue ↗
68chromiumDouble-Free in FlatBuffers Parser::Deserialize (idl_parser.cpp)double-freehighconfirmedGitHub issue ↗
69chromiumHeap Buffer Overflow in flatbuffers::Verify via Reflection VerifyObjectheap-buffer-overflowhighconfirmedGitHub issue ↗
70chromiumHeap Buffer Overflow in FlexBuffers ToString (flexbuffers.h)heap-buffer-overflowhighconfirmedGitHub issue ↗
71chromiumInteger Overflow / Assertion Failure in VP9 Encoder (vp9_aq_complexity.c)integer-overflowhighconfirmedWebM issue ↗
72chromiumNULL Pointer Dereference in GenerateBinaryNULL Pointer Dereference (CWE-476)mediumconfirmedGitHub issue ↗
73chromiumUncontrolled Resource Consumption in PDFium XObject Processing Causes OOM and Tab Crashresource-exhaustionmediumconfirmedChromium issue ↗
74openh264Heap Buffer Overflow in Scene Change Detection (WelsSampleSad8x8_c)heap-buffer-overflowhighconfirmedGitHub issue ↗