Security: secdev/scapy
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Patch the Planet: A guest flag on the final SMB login message switches off required encryptionGHSA-38xg-rhhx-hjfm published
Sep 8, 2026 by gpotter2Moderate -
Patch the Planet: TLS client sends application data after an invalid server CertificateVerifyGHSA-pjgw-v6mx-224h published
Sep 8, 2026 by gpotter2Moderate -
Patch the Planet: One TFTP request can keep the server busy indefinitelyGHSA-v79w-4r7w-q392 published
Sep 8, 2026 by gpotter2Low -
Patch the Planet: An SNMP device can make Scapy's snmpwalk() run foreverGHSA-8fc2-rjg8-qf89 published
Sep 8, 2026 by gpotter2Low -
Patch the Planet: The Scapy SMB server accepts replayed messagesGHSA-q3qv-p2vg-279j published
Sep 8, 2026 by gpotter2Moderate -
Patch the Planet: Scapy TLS client uses a fixed secretGHSA-rxcx-5wjg-vqqm published
Sep 8, 2026 by gpotter2Moderate -
Patch the Planet: A combined certificate and private-key PEM exposes the TLS server key before authenticationGHSA-p899-23mj-p25x published
Sep 8, 2026 by gpotter2Low -
Patch the Planet: HTTP_Client can send an HTTPS request over a reused plaintext socketGHSA-h427-mmxp-q6fr published
Sep 8, 2026 by gpotter2Low -
Patch the Planet: A relay can switch Scapy to a different authentication method mid-exchangeGHSA-fw44-72q9-wj93 published
Sep 8, 2026 by gpotter2Low -
Patch the Planet: A replayed Kerberos reply makes a password change go to the attackerGHSA-xc8f-8v9h-93p5 published
Sep 8, 2026 by gpotter2Moderate