Wojtekmach

Req

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.6%
  • Veröffentlicht 08.06.2026 15:20:57
  • Zuletzt bearbeitet 18.08.2026 15:46:34

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb response bodies. Req's default response pipeline includ...

  • EPSS 0.21%
  • Veröffentlicht 08.06.2026 15:20:24
  • Zuletzt bearbeitet 18.08.2026 19:15:38

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part headers by ...