-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing size validation in two critical paths: 1) Metadata handling in the database layer (add/save methods) lacked image_size_cap checks, as shown by the added validation in the commit diff. 2) The storage layer's data ingestion used CooperativeReader without LimitingReader to enforce size limits, evident from the patch adding the LimitingReader wrapper. These omissions allowed authenticated users to bypass configured size restrictions.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| glance | pip | < 11.0.0a0 | 11.0.0a0 |
Ongoing coverage of React2Shell