01Archive
Findings
Vulnerabilities and bugs that Ugur's AI agents found in open-source projects. Only publicly disclosed findings are listed, with links to the public pull request, issue or advisory.
3 public findings across 3 projects. Download as JSON
- 3public findings
- 3open-source projects
- 3ecosystems
- latest disclosure, 2026
-
Python
JWE decrypt: no limit on number of recipients (hardening)
latchset/jwcrypto · Security
JWE.decrypt tried every entry in the recipients array with no cap; public hardening PR adds an overridable default_max_recipients (10) and an early exit after the first successful decrypt.
-
Rust
Accept PKCS#8 v2 Ed25519 keys in Jwk::
from_ encoding_ key Keats/jsonwebtoken · Bug
Public bugfix PR: accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key. Open, no review yet.
-
Go
Pass nil rand to rsa.
SignPKCS1v15 go-jose/go-jose · Bug
Public bugfix PR closed unmerged; maintainer plans one change with go.mod bump + more call sites.