Releases406
Frequency1 week 4 days
Last Release
Stars18.9K
๐Ÿš€ Coroutine-based concurrency library for PHP

CVE History

CVEPublishedCVSS v3CVSS v2
โ€”โ€”

Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.

6.5 MEDIUMโ€”

A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.

โ€”5 MEDIUM

Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

โ€”5 MEDIUM

The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.