Capnproto is a narrowly scoped serialization and remote-procedure-call (RPC) library that, despite limited product breadth, occupies a prominent position in systems integrating message-passing protocols and data interchange. Its vulnerability profile skews strongly toward critical-severity outcomes, concentrating in parsing and protocol-handling weakness classes including HTTP request smuggling, integer overflow, buffer underflow, and improper input validation—flaws endemic to systems processing untrusted serialized data and network messages. Defenders should monitor this vendor's releases for deployments that depend on the library for inter-service communication; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Capnproto over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48230CRITICAL Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket compression enabled, a buffer und | Nov 21, 2023 | 9.8 | 28 | NO | NO |
CVE-2017-7892HIGH Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap | Apr 17, 2017 | 7.5 | 26 | NO | NO |
CVE-2015-2311CRITICAL Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information fr | Aug 9, 2017 | 9.8 | 25 | NO | NO |
CVE-2026-32240MEDIUM Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larg | Mar 12, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-32239MEDIUM Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly la | Mar 12, 2026 | 6.5 | 23 | NO | NO |
CVE-2015-2310CRITICAL Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive inform | Aug 9, 2017 | 9.1 | 23 | NO | NO |
CVE-2022-46149MEDIUM Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's | Nov 30, 2022 | 5.4 | 21 | NO | NO |
CVE-2015-2312HIGH Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a lar | Aug 9, 2017 | 7.5 | 21 | NO | NO |
CVE-2015-2313HIGH Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of servic | Aug 9, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Capnproto.
Media articles that mention a CVE ID that affects a product developed by Capnproto — matched by CVE ID, not by vendor name.