Releases186
Frequency2 weeks 6 days
Last Release
Stars14.4K
Framework for quickly creating connected applications in Kotlin with minimal effort

CVE History

CVEPublishedCVSS v3CVSS v2
4.7 MEDIUM

JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack

5.3 MEDIUM

In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases

8.7 HIGH4 MEDIUM

SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

3.3 LOW4 MEDIUM

In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations

5.4 MEDIUM5 MEDIUM

In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.

5.4 MEDIUM3.5 LOW

JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.

6.1 MEDIUM5.8 MEDIUM

In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.