FineEnvs/repo2rlenv-cve-patches
repo2rlenv-cve-patches: Harbor dataset on Hugging Face with 19 tasks. Generated by Repo2RLEnv — turning real GitHub repositories into verifiable RL environments.
Tasks
- HTTP Request Smuggling: LF vs CRLF handling in Waitress
- HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
- HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers (Follow-up)
- HTTP Request Smuggling: Content-Length Sent Twice in Waitress
- HTTP Request Smuggling in waitress
- Uncaught Exception (due to a data race) leads to process termination in Waitress
- Waitress has request processing race condition in HTTP pipelining with invalid first request
- HTTP Request Smuggling: Invalid whitespace characters in headers in Waitress
- sqlparse parsing heavily nested list leads to Denial of Service
- Cross-site Scripting in Mistune
- Mistune TOC Anchor Injection XSS
- Flask uses fallback key instead of current signing key
- Flask session does not add Vary: Cookie header when accessed in some ways
- Werkzeug safe join() allows Windows special device names
- Werkzeug safe join() allows Windows special device names with compound extensions
- Werkzeug safe join() allows Windows special device names
- Unintended leak of Proxy-Authorization header in requests
- Requests Session object does not verify requests after making first request with verify=False
- Requests has Insecure Temp File Reuse in its extract zipped paths() utility function