Releases187
Frequency2 weeks 6 days
Last Release
Stars14.5K
Framework for quickly creating connected applications in Kotlin with minimal effort

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 2.1.04.7 MEDIUM

JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack

< 2.1.05.3 MEDIUM

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

= *, = 2.0.08.7 HIGH4 MEDIUM

SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

< 2.0.03.3 LOW4 MEDIUM

In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

< 1.3.05.4 MEDIUM5 MEDIUM

In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.

< 1.2.65.4 MEDIUM3.5 LOW

JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.

<= 1.2.66.1 MEDIUM5.8 MEDIUM

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.