Home/Product/http\ \
Product

http\ \

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-3256
<= 0.53
HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using
9.8CRITICAL
CVE-2018-25160
<= 1.09
HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection o
6.5MEDIUM
CVE-2026-3255
< 1.12
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2
6.5MEDIUM
CVE-2023-44487
all versions
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5HIGH
CVE-2023-26044
>= 0.8.0 and < 1.9.0
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP
5.3MEDIUM
CVE-2023-31486
< 0.083
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configurati
8.1HIGH
CVE-2022-36032
>= 0.7.0 and < 1.7.0
ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component versions star
5.3MEDIUM
CVE-2022-31081
< 6.15
HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could pote
7.3HIGH
CVE-2019-25009
< 0.1.20
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundn
9.8CRITICAL
CVE-2020-35669
<= 0.12.2
An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using
6.1MEDIUM
CVE-2020-25574
< 0.1.20
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() could result in deni
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin