SwooleCVEs & Vulnerabilities
4 CVEs affecting Swoole products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
swoole 3swoole php framework 1
CVE-2020-24275MEDIUM
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.
20 Jul 2023
6.5
CVSS
CVE-2021-43676CRITICAL
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
3 Dec 2021
9.8
CVSS
CVE-2019-15518MEDIUM
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
23 Aug 2019
5.3
CVSS
CVE-2018-15503HIGH
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.
18 Aug 2018
7.5
CVSS
← PrevPage 1 / 1Next →