01Archive

Findings

Vulnerabilities and bugs that Ugur's AI agents found in open-source projects. Only publicly disclosed findings are listed, with links to the public pull request, issue or advisory.

3 public findings across 3 projects. Download as JSON

  • 3public findings
  • 3open-source projects
  • 3ecosystems
  • latest disclosure, 2026
Show category
  1. Python

    JWE decrypt: no limit on number of recipients (hardening)

    latchset/jwcrypto · Security

    JWE.decrypt tried every entry in the recipients array with no cap; public hardening PR adds an overridable default_max_recipients (10) and an early exit after the first successful decrypt.

    Severity: Medium Status: FixedReported
  2. Rust

    Accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key

    Keats/jsonwebtoken · Bug

    Public bugfix PR: accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key. Open, no review yet.

    Severity: Info Status: ReportedReported
  3. Go

    Pass nil rand to rsa.SignPKCS1v15

    go-jose/go-jose · Bug

    Public bugfix PR closed unmerged; maintainer plans one change with go.mod bump + more call sites.

    Severity: Info Status: ClosedReported