Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-12523
Summary
Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/…
Quiche
0.29.3+
HIGH 8.1
CVE-2026-2836
A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the def…
Pingora
0.8.0+
CRITICAL 9.1
CVE-2026-2833
An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora pr…
Pingora
0.8.0+
CRITICAL 9.1
CVE-2026-2835
An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs du…
Pingora
0.8.0+
CRITICAL 9.8
CVE-2026-1229
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by usin…
Circl
1.6.3+
CRITICAL 9.9
CVE-2026-0933
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com…
Wrangler
3.114.17 / 4.59.1+
MEDIUM 5.5
CVE-2025-13353
In gokey versions <0.2.0,
a flaw in the seed decryption logic resulted in passwords incorrectly
being derived solely from the initial vector and th…
Gokey
0.2.0+
MEDIUM 6.5
CVE-2025-7054
Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames.
QUIC connections …
Quiche
0.24.5+
HIGH 7.5
CVE-2025-4821
Impact
Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…
Quiche
0.24.4+
MEDIUM 5.3
CVE-2025-4820
Impact
Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…
Quiche
0.24.4+
CRITICAL 9.1
CVE-2025-6087
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemente…
Create Cloudflare
1.3.0 / 2.49.3+
MEDIUM 6.1
CVE-2025-4366
A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via ma…
Pingora
0.5.0+
CRITICAL 9.8
CVE-2025-4144
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp .…
Workers Oauth Provider
Patch available
MEDIUM 6.1
CVE-2025-4143
The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly valid…
Workers Oauth Provider
Patch available
MEDIUM 5.5
CVE-2021-3978
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided s…
Octorpki
1.4.2+
HIGH 7.1
CVE-2025-0651
Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.
User with a low system privileges can create a …
Warp
2024.12.492.0+
HIGH 7.5
CVE-2024-1765
Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usa…
Quiche
0.19.2+
MEDIUM 5.3
CVE-2024-1410
Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excess…
Quiche
0.19.2+
MEDIUM 6.5
CVE-2024-0212
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged ac…
Cloudflare
4.12.3+
MEDIUM 5.5
CVE-2023-6992
Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c…
Zlib
2023-11-16+
HIGH 8.1
CVE-2023-7078
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Mi…
Miniflare
3.20231030.2+
HIGH 8.0
CVE-2023-7080
The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspe…
Wrangler
2.20.2 / 3.19.0+
MEDIUM 5.7
CVE-2023-7079
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessi…
Wrangler
3.19.0+
MEDIUM 5.3
CVE-2023-6193
quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resou…
Quiche
after 0.19.0
MEDIUM 5.3
CVE-2023-6180
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by res…
Boring
Mitigation only
MEDIUM 5.5
CVE-2023-3747
Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Admi…
Warp
Mitigation only
MEDIUM 5.5
CVE-2023-0238
Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app ins…
Warp
6.29+
HIGH 7.5
CVE-2023-4241
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
Lol Html
1.1.1+
MEDIUM 5.9
CVE-2023-3766
A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specificall…
Odoh Rs
1.0.2+
MEDIUM 5.7
CVE-2023-3348
The Wrangler command line tool (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local deve…
Wrangler
3.1.1+