#1 Dependency Dashboard
openMaintained automatically by Cave. Dismiss false positives with cave deps dismiss.
3 open security alerts
High (1)
- pure-tls
20260403-7c0a399(ocicl) — CL-SEC-2026-0201: Certificate chain trust anchor verified by issuer name only, not signature, in pure-tls — fix:0fefa53
Moderate (2)
- pure-tls
20260403-7c0a399(ocicl) — CL-SEC-2026-0206: Out-of-bounds read parsing attacker-supplied ECHConfig causes uncaught error (remote DoS) in pure-tls — fix:9f9f974 - pure-tls
20260403-7c0a399(ocicl) — CL-SEC-2026-0207: ExtendedKeyUsage not enforced during certificate chain verification in pure-tls — fix:9f9f974
Comments (0)
No comments yet.