TechBriefingJava · React 일일 브리핑 2026.05.10 (Sun) |
|||||||||||||||||||||
|
|||||||||||||||||||||
🎯 오늘의 헤드라인
Runtime
tier S
CVE · 05-04
· score 9.96
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
CVSS 9.8 · CRITICAL
Backend/Java
tier S
CVE · 04-28
· score 9.5
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spri…
CVSS 9.1 · CRITICAL
Meta-Framework
tier S
CVE · 05-07
· score 9.41
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serve() HTTP handler. T…
CVSS 8.6 · HIGH
React Core
tier S
CVE · 05-06
· score 9.25
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopa…
CVSS 7.5 · HIGH
Language/Eco
tier S
CVE · 05-08
· score 8.52
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server due to improper handling of URLs durin…
|
|||||||||||||||||||||
🚀 릴리즈 & 보안 21건
New Releases · 8
Breaking Changes · 5
CVE · 6
Deprecations · 2
|
|||||||||||||||||||||
📈 키워드 트렌드 상승 가중치 기준
|
|||||||||||||||||||||
|
데이터 소스: GitHub Releases · NVD CVE · 공식 블로그 RSS (Spring · React · Kotlin · TypeScript · Next.js · Vite).
중요도 score = tier + source weight + CVSS boost − age penalty (0~10). 생성 시각: 2026-05-10 21:30
구독을 원하지 않으시면 여기에서 해지할 수 있습니다.
|