Comment by pizzalife

6 months ago

I would try to find a better example than CVE-2025-31160. If you ask me, this kind of 'vulnerability' is CVE spam.

Except if you read the blog post we helped a very confused maintainer when they had this dropped on them with no explanation on hacker news except "oooh potential scary heap vuln"