Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-12523 Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/… Quiche 0.29.3+ Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-2836 A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the def… Pingora 0.8.0+ Fix from $1,9502026-03-05 CRITICAL 9.1 CVE-2026-2833 An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora pr… Pingora 0.8.0+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-2835 An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs du… Pingora 0.8.0+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-1229 The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by usin… Circl 1.6.3+ Fix from $2,3002026-02-24 CRITICAL 9.9 CVE-2026-0933 SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com… Wrangler 3.114.17 / 4.59.1+ Fix from $2,3002026-01-20 MEDIUM 5.5 CVE-2025-13353 In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and th… Gokey 0.2.0+ Fix from $1,6002025-12-02 MEDIUM 6.5 CVE-2025-7054 Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections … Quiche 0.24.5+ Fix from $1,6002025-08-07 HIGH 7.5 CVE-2025-4821 Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t… Quiche 0.24.4+ Fix from $1,9502025-06-18 MEDIUM 5.3 CVE-2025-4820 Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t… Quiche 0.24.4+ Fix from $1,6002025-06-18 CRITICAL 9.1 CVE-2025-6087 A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemente… Create Cloudflare 1.3.0 / 2.49.3+ Fix from $2,3002025-06-16 MEDIUM 6.1 CVE-2025-4366 A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via ma… Pingora 0.5.0+ Fix from $1,6002025-05-22 CRITICAL 9.8 CVE-2025-4144 PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp .… Workers Oauth Provider Patch available Fix from $2,3002025-05-01 MEDIUM 6.1 CVE-2025-4143 The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly valid… Workers Oauth Provider Patch available Fix from $1,6002025-05-01 MEDIUM 5.5 CVE-2021-3978 When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided s… Octorpki 1.4.2+ Fix from $1,6002025-01-29 HIGH 7.1 CVE-2025-0651 Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a … Warp 2024.12.492.0+ Fix from $1,9502025-01-22 HIGH 7.5 CVE-2024-1765 Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usa… Quiche 0.19.2+ Fix from $1,9502024-03-12 MEDIUM 5.3 CVE-2024-1410 Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excess… Quiche 0.19.2+ Fix from $1,6002024-03-12 MEDIUM 6.5 CVE-2024-0212 The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged ac… Cloudflare 4.12.3+ Fix from $1,6002024-01-29 MEDIUM 5.5 CVE-2023-6992 Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c… Zlib 2023-11-16+ Fix from $1,6002024-01-04 HIGH 8.1 CVE-2023-7078 Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Mi… Miniflare 3.20231030.2+ Fix from $1,9502023-12-29 HIGH 8.0 CVE-2023-7080 The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspe… Wrangler 2.20.2 / 3.19.0+ Fix from $1,9502023-12-29 MEDIUM 5.7 CVE-2023-7079 Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessi… Wrangler 3.19.0+ Fix from $1,6002023-12-29 MEDIUM 5.3 CVE-2023-6193 quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resou… Quiche after 0.19.0 Fix from $1,6002023-12-12 MEDIUM 5.3 CVE-2023-6180 The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by res… Boring Mitigation only Fix from $1,6002023-12-05 MEDIUM 5.5 CVE-2023-3747 Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Admi… Warp Mitigation only Fix from $1,6002023-09-07 MEDIUM 5.5 CVE-2023-0238 Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app ins… Warp 6.29+ Fix from $1,6002023-08-29 HIGH 7.5 CVE-2023-4241 lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected. Lol Html 1.1.1+ Fix from $1,9502023-08-16 MEDIUM 5.9 CVE-2023-3766 A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specificall… Odoh Rs 1.0.2+ Fix from $1,6002023-08-03 MEDIUM 5.7 CVE-2023-3348 The Wrangler command line tool  (<[email protected] or <[email protected]) was affected by a directory traversal vulnerability when running a local deve… Wrangler 3.1.1+ Fix from $1,6002023-08-03