<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Julia (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/julia.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/julia-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Julia (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-61689 – HTTP.jl is an HTTP client and server functionality for the Julia programming lan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61689</guid>
    <pubDate>Fri, 10 Oct 2025 17:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61689</strong></p>
  <p>HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl did not validate header names/values for illegal characters, allowing CRLF-based header injection and response splitting. This enables HTTP response splitting and header injection, leading to cache poisoning, XSS, session fixation, and more. This issue is fixed in HTTP.jl  `v1.…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-113</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52483 – Registrator is a GitHub app that automates creation of registration pull request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52483</guid>
    <pubDate>Wed, 25 Jun 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52483</strong></p>
  <p>Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities) a shell script injection can occur within the `withpasswd` function. Alternatively, an argument injection is possible in the `gettreesha `function.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52480 – Registrator is a GitHub app that automates creation of registration pull request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52480</guid>
    <pubDate>Wed, 25 Jun 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52480</strong></p>
  <p>Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an argument injection is possible in the `gettreesha()` function. This can then lead to a potential remote code execution. Users should upgrade imm…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52479 – HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl par...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52479</guid>
    <pubDate>Wed, 25 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52479</strong></p>
  <p>HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Identifiers (URIs). URIs.jl prior to version 1.6.0 and HTTP.jl prior to version 1.10.17 allows the construction of URIs containing CR/LF characters. If user input was not otherwise escaped or protected, this can lead to a CRLF injection attack. Users of HTTP.jl should upgrade immedi…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52479">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
