Tag
high
advisory
Credential Disclosure in Renovate via Malicious Pagination Links
1 TTP 1 CVERenovate improperly validates HTTP 'Link' headers during GitHub API interactions, allowing a compromised GitHub server to exfiltrate configured credentials by redirecting pagination requests to an attacker-controlled host.
Renovate +5
credential-access
supply-chain
vulnerability
supply-chain-security
credential-theft
nuget
dependency-management
1t
1c
medium
advisory
SIPSorcery: Malformed UDP Packet Can Remotely Terminate Media Sessions (DoS)
2 TTPsA denial-of-service vulnerability (CVE-2026-54632) exists in the SIPSorcery NuGet package versions <= 10.0.8, allowing an unauthenticated attacker to remotely terminate an active RTP or WebRTC media session by sending a single malformed inbound UDP packet to the RTP/ICE socket, which exploits insufficient length checks and an exception handling flaw.
SIPSorcery
denial-of-service
vulnerability
nuget
2t