Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quiche HIGH 7.5
CVE-2026-12523

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/…

Fix: 0.29.3+
Fix from $1,950 2026-07-14
Pingora HIGH 8.1
CVE-2026-2836

A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the def…

Fix: 0.8.0+
Fix from $1,950 2026-03-05
Pingora CRITICAL 9.1
CVE-2026-2833

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora pr…

Fix: 0.8.0+
Fix from $2,300 2026-03-05
Pingora CRITICAL 9.1
CVE-2026-2835

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs du…

Fix: 0.8.0+
Fix from $2,300 2026-03-05
Circl CRITICAL 9.8
CVE-2026-1229

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by usin…

Fix: 1.6.3+
Fix from $2,300 2026-02-24
Wrangler CRITICAL 9.9
CVE-2026-0933

SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com…

Fix: 3.114.17 / 4.59.1+
Fix from $2,300 2026-01-20
Gokey MEDIUM 5.5
CVE-2025-13353

In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and th…

Fix: 0.2.0+
Fix from $1,600 2025-12-02
Quiche MEDIUM 6.5
CVE-2025-7054

Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections …

Fix: 0.24.5+
Fix from $1,600 2025-08-07
Quiche HIGH 7.5
CVE-2025-4821

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…

Fix: 0.24.4+
Fix from $1,950 2025-06-18
Quiche MEDIUM 5.3
CVE-2025-4820

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…

Fix: 0.24.4+
Fix from $1,600 2025-06-18
Create Cloudflare CRITICAL 9.1
CVE-2025-6087

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemente…

Fix: 1.3.0 / 2.49.3+
Fix from $2,300 2025-06-16
Pingora MEDIUM 6.1
CVE-2025-4366

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via ma…

Fix: 0.5.0+
Fix from $1,600 2025-05-22
Workers Oauth Provider CRITICAL 9.8
CVE-2025-4144

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp .…

Patch available
Fix from $2,300 2025-05-01
Workers Oauth Provider MEDIUM 6.1
CVE-2025-4143

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly valid…

Patch available
Fix from $1,600 2025-05-01
Octorpki MEDIUM 5.5
CVE-2021-3978

When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided s…

Fix: 1.4.2+
Fix from $1,600 2025-01-29
Warp HIGH 7.1
CVE-2025-0651

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a …

Fix: 2024.12.492.0+
Fix from $1,950 2025-01-22
Quiche HIGH 7.5
CVE-2024-1765

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usa…

Fix: 0.19.2+
Fix from $1,950 2024-03-12
Quiche MEDIUM 5.3
CVE-2024-1410

Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excess…

Fix: 0.19.2+
Fix from $1,600 2024-03-12
Cloudflare MEDIUM 6.5
CVE-2024-0212

The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged ac…

Fix: 4.12.3+
Fix from $1,600 2024-01-29
Zlib MEDIUM 5.5
CVE-2023-6992

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c…

Fix: 2023-11-16+
Fix from $1,600 2024-01-04
Miniflare HIGH 8.1
CVE-2023-7078

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Mi…

Fix: 3.20231030.2+
Fix from $1,950 2023-12-29
Wrangler HIGH 8.0
CVE-2023-7080

The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspe…

Fix: 2.20.2 / 3.19.0+
Fix from $1,950 2023-12-29
Wrangler MEDIUM 5.7
CVE-2023-7079

Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessi…

Fix: 3.19.0+
Fix from $1,600 2023-12-29
Quiche MEDIUM 5.3
CVE-2023-6193

quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resou…

Fix: after 0.19.0
Fix from $1,600 2023-12-12
Boring MEDIUM 5.3
CVE-2023-6180

The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by res…

Mitigation only
Fix from $1,600 2023-12-05
Warp MEDIUM 5.5
CVE-2023-3747

Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Admi…

Mitigation only
Fix from $1,600 2023-09-07
Warp MEDIUM 5.5
CVE-2023-0238

Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app ins…

Fix: 6.29+
Fix from $1,600 2023-08-29
Lol Html HIGH 7.5
CVE-2023-4241

lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

Fix: 1.1.1+
Fix from $1,950 2023-08-16
Odoh Rs MEDIUM 5.9
CVE-2023-3766

A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specificall…

Fix: 1.0.2+
Fix from $1,600 2023-08-03
Wrangler MEDIUM 5.7
CVE-2023-3348

The Wrangler command line tool  (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local deve…

Fix: 3.1.1+
Fix from $1,600 2023-08-03