The Pac Resolver Project maintains a specialized proxy auto-config (PAC) resolver component, a narrowly scoped product embedded in browser and system network stacks to dynamically determine proxy settings. Vulnerabilities affecting this product reflect parsing and logic evaluation challenges inherent to PAC script interpretation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pac Resolver Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23406CRITICAL This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is appl | Aug 24, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pac Resolver Project.
Media articles that mention a CVE ID that affects a product developed by Pac Resolver Project — matched by CVE ID, not by vendor name.