Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaBaja (3.7)——Asynchttpclient Async-http-clientAI7/10/20267/10/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 and 2.16.1, Realm.Builder generates the HTTP Digest client nonce with ThreadLocalRandom rather than a cryptographically secure random source. Digest relies on an…
RecibidaAlta (7.5)——Asynchttpclient Async-http-clientAI7/10/20267/10/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT,…
AplazadaMedia (6.9)0.24%—Netty-codec-httpAI26/9/202630/9/2026
Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once per response, including for 1xx informational responses. If a client pipelines an HTTP/1.1…
AplazadaAlta (8.7)0.30%—Netty-codec-http3AI26/9/202628/9/2026
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI,…
AplazadaAlta (8.7)0.34%—Netty-codec-http3AI26/9/202630/9/2026
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiated unidirectional QPACK encoder stream, type 0x02). The handler…
Pendiente de análisisMedia (6.5)1.4%—Netty-codec-httpAI18/9/202624/9/2026
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling. This allows an attacker to bypass…
Pendiente de análisisAlta (8.7)0.35%—Amazon Aws-c-httpAI12/6/202617/6/2026
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To…
AnalizadaAlta (7.4)0.46%—Asynchttpclient Project Async-http-client5/6/202623/7/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin,…
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Uc-http20/2/202417/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.5%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.8%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
ModificadaAlta (7.5)0.55%—Asynchttpclient Project Async-http-client18/1/202317/6/2026
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header…
ModificadaCrítica (9.8)2.0%—Silabs Micrium Uc-http15/11/202217/6/2026
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.
ModificadaAlta (7.5)1.5%—Rc-httpd Project Rc-httpd3/4/202217/6/2026
The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used.
ModificadaAlta (7.5)0.98%—C-http Project C-http2/11/202117/6/2026
Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long url request which is passed to the delimitedread function.
ModificadaAlta (7.5)1.9%—Micrium Uc-http10/2/202117/6/2026
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (7.5)2.6%—Silabs Micrium Uc-http26/1/202117/6/2026
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)40%💥 ExploitXiongmaitech Uc-httpd8/6/201817/6/2026
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
ModificadaAlta (7.5)3.0%—Asynchttpclient Project Async-http-client31/8/201717/6/2026
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.
ModificadaCrítica (9.8)29%—Xiongmaitech Uc-httpd7/4/201717/6/2026
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
ModificadaMedia (4.3)0.83%—Async-http-client Project Async-http-clientRedhat Jboss Fuse24/6/201517/6/2026
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.