
swoole/swoole-src
Releases406
Frequency1 week 4 days
Last Release
Stars18.9K
๐ Coroutine-based concurrency library for PHP
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| โ | โ | ||
Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2. | |||
| 6.5 MEDIUM | โ | ||
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL. | |||
| โ | 5 MEDIUM | ||
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. | |||
| โ | 5 MEDIUM | ||
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV. | |||