Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
1204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.36% | — | Perl Protocol Http2AI | 7/9/2026 | 8/9/2026 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream reaches the CLOSED state, stream_state returns the concurrency slot and clears most of the stream's keys, but the entry itself stays in the connection… | |
| Analizada | Alta (7.5) | 0.74% | — | Fastify/http-proxy | 3/9/2026 | 9/9/2026 | @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Httpx2AI | 2/9/2026 | 9/9/2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bounded pieces to the application. A 64 KiB compressed chunk can expand to… | |
| Pendiente de análisis | Alta (8.1) | 0.11% | — | Httpx2AIHttpcore2AI | 2/9/2026 | 9/9/2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because the TLS upgrade condition only recognizes https. HTTPX2… | |
| Pendiente de análisis | Media (5.6) | 0.22% | — | Httpx2AI | 2/9/2026 | 9/9/2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently… | |
| Pendiente de análisis | Media (5.3) | 0.32% | — | Httpx2AI | 2/9/2026 | 9/9/2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element… | |
| Pendiente de análisis | Media (5.9) | 0.32% | — | Httpx2AI | 2/9/2026 | 9/9/2026 | HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-controlled or compromised SSE endpoint splits one unterminated line across many… | |
| Pendiente de análisis | Media (6.5) | 0.32% | — | Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI | 1/9/2026 | 1/9/2026 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion… | |
| Aplazada | Alta (8.7) | 0.70% | — | CohttpAI | 29/8/2026 | 1/9/2026 | The cohttp package before 6.3.0 for OCaml allows directory traversal. | |
| Aplazada | Alta (7.5) | 0.49% | — | Alos HttpAI | 28/8/2026 | 9/9/2026 | ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking… | |
| Aplazada | Alta (8.2) | 0.45% | — | Cpp-httplibAI | 28/8/2026 | 9/9/2026 | cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the… | |
| Aplazada | Media (5.3) | 0.46% | — | CPP HttplibAI | 28/8/2026 | 9/9/2026 | cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer field to inject additional headers or split the HTTP response. Unlike every other… | |
| Aplazada | Alta (8.8) | 0.78% | — | Openwrt Luci-app-https-dns-proxyAI | 27/8/2026 | 1/9/2026 | An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter | |
| Aplazada | Crítica (10) | 0.78% | — | Ui-tars-desktop Mcp-http-serverAIAgent-infra Mcp-server-commandsAIAgent-infra Mcp-server-filesystemAI | 27/8/2026 | 23/9/2026 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a… | |
| Aplazada | Alta (8.2) | 0.52% | — | Typelevel Http4sAI | 26/8/2026 | 9/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/src/main/scala/org/http4s/ember/core/h2/Hpack.scala concatenates HEADERS and… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Beijing Tongtech TongwebAIVmware HttpinvokerserviceexporterAI | 25/8/2026 | 31/8/2026 | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | |
| Aplazada | Crítica (9.3) | 0.93% | — | Openwrt UhttpdAI | 25/8/2026 | 3/9/2026 | The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username… | |
| Aplazada | Alta (7.5) | 0.72% | — | Apache Http ServerAIMOD Auth OpenidcAI | 21/8/2026 | 18/9/2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is… | |
| Aplazada | Alta (7.5) | 0.58% | — | Acme Mini HttpdAI | 17/8/2026 | 9/9/2026 | An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function | |
| Pendiente de análisis | Media (6.3) | 0.57% | — | Actix-httpAI | 14/8/2026 | 24/9/2026 | actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and… | |
| Aplazada | Alta (7.4) | 0.48% | — | Typelevel BlazeAITypelevel Http4sAI | 12/8/2026 | 9/9/2026 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAI | 12/8/2026 | 10/9/2026 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated… | |
| Analizada | Crítica (9.1) | 0.33% | — | Apache Httpclient | 11/8/2026 | 24/9/2026 | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by… | |
| Aplazada | Crítica (9.1) | 0.44% | — | LighttpdAIUnknown Vendor Product FirmwareAI | 4/8/2026 | 9/9/2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | |
| Aplazada | Crítica (9.1) | 0.44% | — | LighttpdAI | 4/8/2026 | 9/9/2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. |