swoole/swoole-src
Releases408
Frequency1 week 4 days
Last Release
Stars18.9K
๐ Coroutine-based concurrency library for PHP
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| โ | โ | โ | ||
Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2. | ||||
| โ | 6.5 MEDIUM | โ | ||
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL. | ||||
| โ | โ | 5 MEDIUM | ||
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. | ||||
| โ | โ | 5 MEDIUM | ||
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV. | ||||