Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:brew/locust

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2024-49766 is a vulnerability in Locust related to Werkzeug's safe_join function on Windows systems running Python versions earlier than 3.11. The issue arises because os.path.isabs() does not properly detect UNC paths, allowing safe_join to produce unsafe paths that could lead to unintended data access. Systems using Python 3.11 or later, or non-Windows platforms, are not affected. A patch is available to address this issue.

Join the discussion

CVE-2024-6221 is a high-severity vulnerability in the Locust product related to the flask-cors library version 4.0.1. It causes the Access-Control-Allow-Private-Network CORS header to be set to true by default without configuration options. This misconfiguration can expose private network resources to unauthorized external access, increasing the risk of data breaches and network intrusions. The vulnerability affects Locust versions from 2.2.1 up to but not including 2.31.4_1. A patch is available to address this issue.

Join the discussion

A vulnerability in urllib3 used by Locust (CVE-2025-50181) causes the 'retries' parameter on PoolManager instantiation to be ignored when attempting to disable HTTP redirects. This means that disabling redirects at the PoolManager level does not work as intended, potentially leaving applications vulnerable to SSRF exploitation if they rely on this mechanism for mitigation. The issue affects Locust versions from 2.2.1 up to but not including 2.37.10_2. A patch is available to address this behavior.

Join the discussion

When the `session` object is accessed, Flask should set the `Vary: Cookie` header. This instructs caches not to cache the response, as it may contain information specific to a logged in user. This is handled in most cases, but some forms of access such as the Python `in` operator were overlooked. The severity depends on the application's use of the session, and the cache's behavior regarding cookies. The risk depends on all these conditions being met. 1. The application must be hosted behind a caching proxy that does not ignore responses with cookies. 2. The application does not set a `Cache-Control` header to indicate that a page is private or should not be cached. 3. The application accesses the session in a way that does not access the values, only the keys, and does not mutate the session.

Join the discussion

A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion

### Impact If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack. ### Patches v1.2.1 ### Workarounds Users should create a new Unpacker instead of reusing the same Unpacker after an error occurs. Applying the above patch can prevent SEGV, but reusing the Streaming Unpacker after it has encountered an error will not yield correct data. If an error occurs during Streaming Unpacking, the Stream and Streaming Unpacker should be discarded. Therefore, this is not just a workaround but the correct solution. The above patch only prevents crashes from incorrect usage.

Join the discussion

### Impact The `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. ### Affected usages **Standard usage of the Requests library is not affected by this vulnerability.** Only applications that call `extract_zipped_paths()` directly are impacted. ### Remediation Upgrade to at least Requests 2.33.0, where the library now extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access.

Join the discussion

CVE-2026-45409 is a denial-of-service vulnerability in the idna.encode() function used by the Locust package. Specially crafted inputs can cause the function to consume excessive resources due to incomplete input length checks, leading to potential service disruption. The issue is a follow-up to CVE-2024-3651, where the original fix was incomplete. Starting with version 3.14, idna rejects long inputs early to minimize resource consumption, with further improvements in version 3.15. Enforcing domain name length limits before calling idna.encode() can mitigate the issue.

Join the discussion

This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. ### Impact A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. ### Patches Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). ### Workarounds Domain names cannot exceed 253 characters in length, if this length limit is enforced prior to passing the domain to the `idna.encode()` function it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.

Join the discussion

pytest through 9.0.2 on UNIX relies on directories with the `/tmp/pytest-of-{user}` name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Join the discussion

Showing 1 to 10 of 25 results

Filters:Package: pkg:brew/locust
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses