Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
1204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.36% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender… | |
| Pendiente de análisis | Media (5.9) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the… | |
| Pendiente de análisis | Media (6.8) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the… | |
| Pendiente de análisis | Alta (7.5) | 0.66% | — | Reactphp HttpAI | 16/9/2026 | 30/9/2026 | react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete… | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember… | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAIErik Hjortsberg EmberAI | 15/9/2026 | 17/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or PUSH_PROMISE frame without END_HEADERS, H2Connection buffers the header block and subsequent CONTINUATION fragments without a size bound. A remote peer can keep an incomplete block open and exhaust… | |
| Aplazada | Alta (8.7) | 0.50% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an Ember server is behind a keep-alive intermediary that selects a different occurrence, an… | |
| Aplazada | Media (6.8) | 0.51% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie. A cookie for example.com can consequently be sent to an attacker-controlled… | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAI | 15/9/2026 | 17/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejects extended payload lengths above Integer.MAX_VALUE but permits negative 64-bit lengths. A remote client that completes a WebSocket handshake through an Ember server can send such a frame, causing… | |
| Aplazada | Media (5.9) | 0.40% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc values because of parallel or retried requests, the stored counter remains below… | |
| Aplazada | Alta (8.7) | 0.48% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and decodes header bytes with the platform default charset. Values such as Chunked are not recognized, values such as notchunked are incorrectly… | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled through withHttp2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS for peer-created streams. One unauthenticated connection can open an unbounded number of streams, each retaining per-stream state until… | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the network rather than bytes consumed by the application, while each stream stores DATA in an unbounded channel. A hostile peer can therefore send a body… | |
| Aplazada | Media (5.4) | 0.37% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the required CRLF. When an intermediary forwards chunked data without re-encoding and… | |
| Aplazada | Media (6.8) | 0.40% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejecting public suffixes. A malicious or compromised server contacted through the same… | |
| Aplazada | Alta (7.5) | 0.63% | — | Typelevel Http4sAI | 15/9/2026 | 17/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue sending PING, SETTINGS, or DATA frames that cause Ember to enqueue… | |
| Aplazada | Media (5.9) | 0.28% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority comparison excludes the URI scheme. A same-authority redirect from HTTPS to HTTP therefore preserves… | |
| Aplazada | Media (4.8) | 0.33% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or control characters. An application that constructs a ResponseCookie from unvalidated input can therefore… | |
| Aplazada | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAIHttp4s-ember-serverAITypelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket… | |
| Aplazada | Alta (7.5) | 0.77% | — | Typelevel Http4sAI | 15/9/2026 | 17/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an application that protects at least one route with DigestAuth, an unauthenticated… | |
| Aplazada | Crítica (9.2) | 0.57% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a keep-alive intermediary that forwards both… | |
| Aplazada | Media (5.9) | 0.76% | — | Typelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request containing percent-encoded slash or backslash separators can turn an accepted segment… | |
| Aplazada | Alta (8.7) | 0.51% | — | Netty-incubator-codec-ohttpAI | 15/9/2026 | 30/9/2026 | netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequestResponseContext.java allocates a pooled direct ByteBuf for decrypted plaintext… | |
| Aplazada | Alta (7.5) | 0.63% | — | Http4kAI | 14/9/2026 | 30/9/2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompressed size. An unauthenticated client can send a small gzip-encoded request body that… | |
| Aplazada | Crítica (9.4) | 0.45% | — | FroxlorAINginxAIApache Http ServerAI | 14/9/2026 | 23/9/2026 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during cron rebuild,… |