Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2026-49755
- EPSS 0.6%
- Veröffentlicht 08.06.2026 15:20:57
- Zuletzt bearbeitet 18.08.2026 15:46:34
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb response bodies. Req's default response pipeline includ...
3.7
CVE-2026-49756
- EPSS 0.21%
- Veröffentlicht 08.06.2026 15:20:24
- Zuletzt bearbeitet 18.08.2026 19:15:38
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by ...
1