reactphp records
2 published records for vendor reactphp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2022-36032No exploit | ReactPHP's HTTP server parses encoded cookie names so malicious `__Host-` and `__Secure-` cookies can be sentreactphp · http · CWE-20 | Medium5.3 | — | 1.0% | Sep 6, 2022 |
21Monitor | CVE-2023-26044No exploit | ReactPHP's HTTP server continues parsing unused multipart parts after reaching limitsreactphp · http · CWE-400 | Medium5.3 | — | 0.7% | May 17, 2023 |
- CVE-2022-3603221Monitor
ReactPHP's HTTP server parses encoded cookie names so malicious `__Host-` and `__Secure-` cookies can be sent
MediumCVSS 5.3No exploitEPSS 1%reactphp · httpSep 6, 2022
- CVE-2023-2604421Monitor
ReactPHP's HTTP server continues parsing unused multipart parts after reaching limits
MediumCVSS 5.3No exploitEPSS 1%reactphp · httpMay 17, 2023