Записи typelevel
11 опубликованных записей вендора typelevel.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-23 Relative Path Traversal1
- CWE-295 Improper Certificate Validation1
- CWE-346 Origin Validation Error1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-31183Эксплойта нет | mTLS client verification is skipped in fs2 on Node.jstypelevel · fs2 · CWE-295 | Критическая9,8 | — | 0,8 % | 1 авг. 2022 г. |
36Наблюдать | CVE-2021-39185Эксплойта нет | Default CORS config allows any origin with credentialstypelevel · http4s · CWE-346 | Критическая9,1 | — | 0,6 % | 1 сент. 2021 г. |
32Наблюдать | CVE-2020-5280Эксплойта нет | Local file inclusion vulnerability in http4stypelevel · http4s · CWE-23 | Высокая7,5 | — | 7,0 % | 25 мар. 2020 г. |
31Наблюдать | CVE-2021-21294Эксплойта нет | Unbounded connection acceptance in http4s-blaze-servertypelevel · http4s · CWE-400 | Высокая7,5 | — | 2,1 % | 2 февр. 2021 г. |
31Наблюдать | CVE-2021-21293Эксплойта нет | Unbounded connection acceptance leads to file handle exhaustiontypelevel · blaze · CWE-400 | Высокая7,5 | — | 2,1 % | 2 февр. 2021 г. |
30Наблюдать | CVE-2023-50730Эксплойта нет | Grackle has StackOverflowError in GraphQL query processingtypelevel · grackle · CWE-400 | Высокая7,5 | — | 0,8 % | 22 дек. 2023 г. |
30Наблюдать | CVE-2022-21653Эксплойта нет | Hash collision in typelevel jawntypelevel · jawn · CWE-400 | Высокая7,5 | — | 0,8 % | 5 янв. 2022 г. |
25Наблюдать | CVE-2025-59822Эксплойта нет | Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sectiontypelevel · http4s · CWE-444 | Средняя6,3 | — | 0,4 % | 23 сент. 2025 г. |
23Наблюдать | CVE-2021-32643Эксплойта нет | StaticFile.fromUrl can leak presence of a directorytypelevel · http4s · CWE-22 | Средняя5,8 | — | 1,4 % | 27 мая 2021 г. |
21Наблюдать | CVE-2023-22465Эксплойта нет | Http4s has fatal error parsing User-Agent and Server headerstypelevel · http4s · CWE-20 | Средняя5,3 | — | 0,8 % | 4 янв. 2023 г. |
18Наблюдать | CVE-2021-41084Эксплойта нет | Response Splitting from unsanitized headers in http4stypelevel · http4s · CWE-918 | Средняя4,7 | — | 1,2 % | 21 сент. 2021 г. |
- CVE-2022-3118339Наблюдать
mTLS client verification is skipped in fs2 on Node.js
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %typelevel · fs21 авг. 2022 г.
- CVE-2021-3918536Наблюдать
Default CORS config allows any origin with credentials
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %typelevel · http4s1 сент. 2021 г.
- CVE-2020-528032Наблюдать
Local file inclusion vulnerability in http4s
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %typelevel · http4s25 мар. 2020 г.
- CVE-2021-2129431Наблюдать
Unbounded connection acceptance in http4s-blaze-server
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %typelevel · http4s2 февр. 2021 г.
- CVE-2021-2129331Наблюдать
Unbounded connection acceptance leads to file handle exhaustion
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %typelevel · blaze2 февр. 2021 г.
- CVE-2023-5073030Наблюдать
Grackle has StackOverflowError in GraphQL query processing
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %typelevel · grackle22 дек. 2023 г.
- CVE-2022-2165330Наблюдать
Hash collision in typelevel jawn
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %typelevel · jawn5 янв. 2022 г.
- CVE-2025-5982225Наблюдать
Http4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
СредняяCVSS 6,3Эксплойта нетEPSS 0 %typelevel · http4s23 сент. 2025 г.
- CVE-2021-3264323Наблюдать
StaticFile.fromUrl can leak presence of a directory
СредняяCVSS 5,8Эксплойта нетEPSS 1 %typelevel · http4s27 мая 2021 г.
- CVE-2023-2246521Наблюдать
Http4s has fatal error parsing User-Agent and Server headers
СредняяCVSS 5,3Эксплойта нетEPSS 1 %typelevel · http4s4 янв. 2023 г.
- CVE-2021-4108418Наблюдать
Response Splitting from unsanitized headers in http4s
СредняяCVSS 4,7Эксплойта нетEPSS 1 %typelevel · http4s21 сент. 2021 г.