Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-26137

    All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values in the addHeader and addCookie functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

    Last Modified: Nov 21, 2024
    Published: Jul 06, 2023

    CVE-2023-26138

    All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

    Last Modified: Nov 21, 2024
    Published: Jul 06, 2023

    CVE-2022-3959

    drogon Session Hash small space of random values

    Last Modified: Apr 15, 2025
    Published: Nov 11, 2022

    CVE-2022-25297

    Arbitrary File Write

    Last Modified: Nov 21, 2024
    Published: Feb 21, 2022

    CVE-2021-35397

    A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted.

    Last Modified: Nov 21, 2024
    Published: Aug 04, 2021
    Items Per Page
    Drogon Vulnerabilities & Security CVEs | CVE-DB