dfir-unfurl
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting dfir-unfurlpage 1 of 1
- CVE-2026-40035CRITICALCVSS 9.1EG 9.12026-04-08
vulnerable: 20200629 ... 20250810 (27 versions)
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empt…
- CVE-2026-40036HIGHCVSS 7.5EG 7.5✓ Fixed in 202604052026-04-08
vulnerable: 20200629 ... 20250810 (27 versions)
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/v…
Check whether dfir-unfurl is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for dfir-unfurl CVEs against the assets you own.
Start Free Scan →