{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-03T11:15:24.485","vulnerabilities":[{"cve":{"id":"CVE-2023-26146","sourceIdentifier":"report@snyk.io","published":"2023-09-29T05:15:46.540","lastModified":"2024-11-21T07:50:52.447","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered."},{"lang":"es","value":"Todas las versiones del paquete ithewei/libhv son vulnerables a Cross-Site Scripting (XSS), de modo que cuando la aplicación entrega un archivo con un nombre que contiene un payload malicioso, el nombre del archivo se muestra sin la sanitización adecuada cuando se procesa."}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"report@snyk.io","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ithewei:libhv:*:*:*:*:*:*:*:*","matchCriteriaId":"02035540-1A6E-46F6-A215-8ADBE8A24F04"}]}]}],"references":[{"url":"https://gist.github.com/dellalibera/c53448135480cbe12257c4b413a90d20","source":"report@snyk.io","tags":["Exploit"]},{"url":"https://security.snyk.io/vuln/SNYK-UNMANAGED-ITHEWEILIBHV-5730766","source":"report@snyk.io","tags":["Exploit","Third Party Advisory"]},{"url":"https://gist.github.com/dellalibera/c53448135480cbe12257c4b413a90d20","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"https://security.snyk.io/vuln/SNYK-UNMANAGED-ITHEWEILIBHV-5730766","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}