CVE-2020-28441: Conf-Cfg-Ini Project Conf-Cfg-Ini

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

Affected products

Published 2022-07-25. Last modified 2026-06-17.