Octobox is a GitHub notification management tool with a narrow product scope centered on its core notification-triage application. The recurring vulnerability pattern involves resource-exhaustion and algorithmic-complexity issues, specifically unbounded resource allocation and regular expression denial-of-service conditions that can degrade service availability under adversarial input.
The number and severity of CVEs published that impact products developed by Octobox Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32848HIGH Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted search query string that will trigge | Feb 20, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Octobox Project.
Media articles that mention a CVE ID that affects a product developed by Octobox Project — matched by CVE ID, not by vendor name.