The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade pymongo to version 4.18.2 or higher.
Affected versions of this package are vulnerable to Integer Overflow or Wraparound in buffer_assure_space() in bson/buffer.c of the bundled C extension, where buffer->position + size is computed in a signed int and the guard meant to catch the wraparound is written as new_size < buffer->position, a test that depends on signed overflow and is therefore undefined behavior a compiler may discard. An attacker can write past the end of an allocated buffer inside the encoding process by placing a value large enough that a single document's encoded size crosses INT_MAX, so the wrapped negative result satisfies the space check and a short allocation is used for a longer write. This requires the application to encode attacker-influenced data approaching 2 GiB in one document, a build that uses the C extension rather than the pure Python encoder, and a compiler that eliminated the check.