/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-43799

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-43799

Severity

5.0

Medium

CVSS V3

Summary

send vulnerable to template injection that can lead to XSS

Description

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing