Framework for quickly creating connected applications in Kotlin with minimal effort

CVE History

CVEPublishedCVSS v2CVSS v3
CVE-2022-381796.1 MEDIUMN/A
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
CVE-2022-381806.5 MEDIUMN/A
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
CVE-2022-299304.9 MEDIUM4 MEDIUM
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
CVE-2022-290352.7 LOW4 MEDIUM
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
CVE-2020-52077.5 HIGH5 MEDIUM
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
CVE-2019-193895.4 MEDIUM3.5 LOW
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
CVE-2019-197036.1 MEDIUM5.8 MEDIUM
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.