Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
1204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.24% | — | Http4k-coreAI | 27/9/2026 | 30/9/2026 | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used… | |
| Aplazada | Media (6.3) | 0.34% | — | Http4kAI | 27/9/2026 | 30/9/2026 | http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on the Host header by default in reverseProxy() and reverseProxyRouting() when dispatching to configured virtual hosts. If these functions are deployed as a public-facing inbound HTTP handler with… | |
| Aplazada | Media (6.9) | 0.24% | — | Netty-codec-httpAI | 26/9/2026 | 30/9/2026 | Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once per response, including for 1xx informational responses. If a client pipelines an HTTP/1.1… | |
| Aplazada | Alta (8.7) | 0.33% | — | Netty Codec Http3AI | 26/9/2026 | 28/9/2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of an absolute-form HTTP/1 request-target. In HttpConversionUtil.toHttp3Headers(HttpMessage, boolean) — reached via… | |
| Aplazada | Alta (8.7) | 0.30% | — | Netty-codec-http3AI | 26/9/2026 | 28/9/2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI,… | |
| Aplazada | Alta (8.7) | 0.34% | — | Netty-codec-http3AI | 26/9/2026 | 30/9/2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiated unidirectional QPACK encoder stream, type 0x02). The handler… | |
| Aplazada | Alta (8.7) | 0.34% | — | Netty Codec Http3AI | 26/9/2026 | 2/10/2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the number of continuation bytes it will process. A remote, unauthenticated peer can open a… | |
| Aplazada | Alta (8.7) | 0.38% | — | Netty Codec Http3AI | 26/9/2026 | 28/9/2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker for every encoded field section that references the QPACK dynamic table, keyed by the peer-controlled QUIC stream ID,… | |
| Aplazada | Media (6.9) | 0.24% | — | Netty Codec Http3AI | 26/9/2026 | 28/9/2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote unauthenticated peer can send a single HEADERS frame… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Http4s-scala-xmlAI | 24/9/2026 | 30/9/2026 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the… | |
| Aplazada | Baja (2.1) | 0.24% | — | Fast Fac1900rAIUhttpdAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Busybox HttpdAI | 23/9/2026 | 25/9/2026 | BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | Busybox HttpdAI | 23/9/2026 | 25/9/2026 | BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. | |
| Aplazada | Crítica (9.1) | 0.27% | — | Apache Http ServerAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users. | |
| Aplazada | Alta (8.4) | 0.13% | — | Apache Http ServerAIOpensslAI | 22/9/2026 | 23/9/2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution. | |
| Aplazada | Media (5.6) | 0.24% | — | Tauri Http PluginAIReqwestAI | 22/9/2026 | 22/9/2026 | The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who… | |
| Pendiente de análisis | Media (6.5) | 1.4% | — | Netty-codec-httpAI | 18/9/2026 | 24/9/2026 | A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling. This allows an attacker to bypass… | |
| Aplazada | Alta (8.2) | 0.45% | — | Http-cache-semanticsAI | 18/9/2026 | 23/9/2026 | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different… | |
| Aplazada | Alta (8.7) | 0.53% | — | Http-cache-semanticsAI | 18/9/2026 | 23/9/2026 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's… | |
| Aplazada | Alta (8.1) | 0.58% | — | Http4kAI | 18/9/2026 | 24/9/2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication… | |
| Aplazada | Media (6.5) | 0.26% | — | Http4k-security-digestAI | 18/9/2026 | 24/9/2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response with hardcoded MD5. Deployments configured for SHA-256 therefore receive weaker… | |
| Aplazada | Alta (8.7) | 0.52% | — | EspasynchttpserverAI | 17/9/2026 | 24/9/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly… | |
| Pendiente de análisis | Media (5.9) | 0.27% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and… | |
| Pendiente de análisis | Baja (3.7) | 0.41% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a… |