Vulnerabilities > Linecorp > Armeria > 0.86.0

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5
2023-07-25 CVE-2023-38493 Unspecified vulnerability in Linecorp Armeria
Armeria is a microservice framework Spring supports Matrix variables.
network
low complexity
linecorp
7.5
2021-12-02 CVE-2021-43795 Path Traversal vulnerability in Linecorp Armeria
Armeria is an open source microservice framework.
network
low complexity
linecorp CWE-22
5.0
2019-12-06 CVE-2019-16771 Injection vulnerability in Linecorp Armeria
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response.
network
low complexity
linecorp CWE-74
5.0