Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Capnproto

First CVE: Apr 17, 2017Active for: 9 yearsTotal CVEs: 9

Capnproto is a narrowly scoped serialization and remote-procedure-call (RPC) library that, despite limited product breadth, occupies a prominent position in systems integrating message-passing protocols and data interchange. Its vulnerability profile skews strongly toward critical-severity outcomes, concentrating in parsing and protocol-handling weakness classes including HTTP request smuggling, integer overflow, buffer underflow, and improper input validation—flaws endemic to systems processing untrusted serialized data and network messages. Defenders should monitor this vendor's releases for deployments that depend on the library for inter-service communication; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Capnproto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2017
9 years ago
Most Recent CVE
Mar 12, 2026
135 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-48230CRITICAL
Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket compression enabled, a buffer und
Nov 21, 20239.828NONO
CVE-2017-7892HIGH
Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap
Apr 17, 20177.526NONO
CVE-2015-2311CRITICAL
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information fr
Aug 9, 20179.825NONO
CVE-2026-32240MEDIUM
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larg
Mar 12, 20266.523NONO
CVE-2026-32239MEDIUM
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly la
Mar 12, 20266.523NONO
CVE-2015-2310CRITICAL
Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive inform
Aug 9, 20179.123NONO
CVE-2022-46149MEDIUM
Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's
Nov 30, 20225.421NONO
CVE-2015-2312HIGH
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a lar
Aug 9, 20177.521NONO
CVE-2015-2313HIGH
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of servic
Aug 9, 20177.520NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
33%
33%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Capnproto.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Capnproto — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Capnproto's Products

View all 3 CNAs →

Top CWEs