react/http Security Advisories for v1.0.0 (4)
-
Unbounded HTTP Client Response Header Buffering Leads to Memory Exhaustion DoS in react/http
Affected version: >=1.0.0,<1.11.1
Reported by:
FriendsOfPHP/security-advisories -
A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
PKSA-7xc4-r5ry-fg9s CVE-2026-84997
Affected version: >=0.6.0,<1.11.1
Reported by:
FriendsOfPHP/security-advisories -
[MEDIUM] ReactPHP's HTTP server continues parsing unused multipart parts after reaching limits
PKSA-wsbn-q9bd-w7z2 CVE-2023-26044 GHSA-95x4-j7vc-h8mf
Affected version: >=0.8.0,<1.9.0
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] ReactPHP's HTTP server parses encoded cookie names so malicious `__Host-` and `__Secure-` cookies can be sent
PKSA-kwfb-dvpm-qtpb CVE-2022-36032 GHSA-w3w9-vrf5-8mx8
Affected version: >=0.7.0,<1.7.0
Reported by:
GitHub, FriendsOfPHP/security-advisories