Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-1867

    HTTP Response Smuggling Vulnerability in libhv

    Last Modified: Apr 15, 2026
    Published: Mar 03, 2025

    CVE-2023-26147

    All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content, like for example additional headers or new response body, leading to a potential XSS vulnerability.

    Last Modified: Nov 21, 2024
    Published: Sep 29, 2023

    CVE-2023-26148

    All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

    Last Modified: Nov 21, 2024
    Published: Sep 29, 2023

    CVE-2023-26146

    All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.

    Last Modified: Nov 21, 2024
    Published: Sep 29, 2023
    Items Per Page