dash-uploader
Upload large files using resumable.js
Activity
- Latest release
- 1y ago
- Total releases
- 16
- Cadence
- ~20 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Apr 26, 2020
| Version | Released | |
|---|---|---|
0.7.0a2
pre
1 CVE
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.1
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.7.0a1
pre
1 CVE
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.4.2
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.4.1
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.3.1
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.2.4
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.2.3
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2026-38360
PYSEC-2026-320
GHSA-3rf6-x59v-5jfv
Jun 29, 2026
dash-uploader has a directory traversal vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
ImpactAn unauthenticated path traversal vulnerability exists in dash-uploader versions 0.1.0 through 0.7.0a2. The library's HTTP request handler at A single unauthenticated When the chosen target is a Python Affected versionsAll 16 published PyPI releases ( MitigationReplace While a replacement is being deployed, mitigations include:
Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 4 more Show less
0.6.0
0.6.1
0.7.0a1
0.7.0a2
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-38361
PYSEC-2026-37
May 08, 2026
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.3
0.2.4
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
+ 2 more Show less
0.6.0
0.6.1
Fixed in
0.7.0a1
References
Updated May 20, 2026 · Source: OSV.dev |