issues Search Results · language:Dune language:TypeScript language:JavaScript language:PHP language:HTML linked:pr
Filter by
6M results
Describe the bug
The buildPaginatedUrl utility in eventFetchUtils.js suffers from a URL Parameter Pollution vulnerability. Because it
relies on raw string concatenation ( page=x size=y), it blindly appends ...
bug
State-changing endpoints lack CSRF token validation allowing cross-site request forgery attacks.
Admin promotion and automatic promotion run in parallel causing event capacity to be exceeded.
No error notifications when cron fails, causing 1000s of users to miss event reminders.
Rapid button clicks trigger multiple payment requests, both succeed and charge user twice.
Regular users can access and modify organization settings without proper authorization.
Server and client render different HTML causing flickering and layout shifts.
Describe the bug
The buildGitHubProxyUrl utility contains two critical SSRF (Server-Side Request Forgery) injection vectors that could
allow an attacker to steal backend API tokens or access unauthorized ...
bug
Event webhooks fail silently with no retries. Notifications never reach external services.
Peak traffic exhausts connection pool causing cascading failures and Too many connections errors.

Learn how you can use GitHub Issues to plan and track your work.
Save views for sprints, backlogs, teams, or releases. Rank, sort, and filter issues to suit the occasion. The possibilities are endless.Learn more about GitHub IssuesProTip! Restrict your search to the title by using the in:title qualifier.