CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-29904MEDIUM | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible CWE-444Mar 12, 2025 | CVSS5.3v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49580MEDIUM | JetBrains Ktor information disclosureIn JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure CWE-524Oct 17, 2024 | CVSS5.3v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45613MEDIUM | In JetBrains Ktor before 2.3.5 server certificates were not verified CWE-295Oct 9, 2023 | CVSS6.8v3.1 | EPSS0.298% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45612HIGH | In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE CWE-611Oct 9, 2023 | CVSS8.6v3.1 | EPSS0.595% | PoCs7 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message CWE-209Jun 1, 2023 | CVSS3.3v3.1 | EPSS0.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2022-48476HIGH | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | CVSS7.5v3.1 | EPSS0.751% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38180MEDIUM | JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication providerIn JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases CWE-287Aug 12, 2022 | CVSS5.3v3.1 | EPSS0.701% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38179MEDIUM | JetBrains Ktor before 2.1.0 was vulnerable to a Reflect File Download attackJetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack | CVSS4.7v3.1 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29930HIGH | SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1. | CVSS8.7v3.1 | EPSS0.855% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations CWE-330Apr 11, 2022 | CVSS3.3v3.1 | EPSS0.611% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |