Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Capnproto MEDIUM 6.5
CVE-2026-32239

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, …

Fix: 1.4.0+
Fix from $1,600 2026-03-12
Capnproto MEDIUM 6.5
CVE-2026-32240

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size pa…

Fix: 1.4.0+
Fix from $1,600 2026-03-12
Capnproto CRITICAL 9.8
CVE-2023-48230

Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket co…

Patch available
Fix from $2,300 2023-11-21
Capnp MEDIUM 5.4
CVE-2022-46149

Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as we…

Fix: 0.7.1 / 0.9.2+
Fix from $1,600 2022-11-30
Capnproto CRITICAL 9.8
CVE-2015-2311

Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly …

Fix: after 0.4.1.0
Fix from $2,300 2017-08-09
Capnproto HIGH 7.5
CVE-2015-2312

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource con…

Fix: after 0.4.1.0
Fix from $1,950 2017-08-09
Capnproto HIGH 7.5
CVE-2015-2313

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote pe…

Fix: after 0.4.1.0
Fix from $1,950 2017-08-09
Capnproto CRITICAL 9.1
CVE-2015-2310

Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or p…

Fix: 0.4.1.1 / 0.5.1.1+
Fix from $2,300 2017-08-09
Capnproto HIGH 7.5
CVE-2017-7892

Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit l…

Fix: after 0.5.3
Fix from $1,950 2017-04-17