Charles is a focused HTTP proxy and debugging tool used by developers for monitoring, modifying, and testing network traffic in client applications. Its modest vulnerability surface centers on the Charles proxy product itself, with recurring issues in race conditions under concurrent request handling and XML external entity reference validation, reflecting the parsing and synchronization demands of an intercepting proxy. Current severity, exploitation activity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Charlesproxy over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15358HIGH Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option. | Aug 3, 2018 | 7.0 | 32 | NO | YES |
CVE-2018-19244HIGH An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet net | Nov 13, 2018 | 8.6 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Charlesproxy.
Media articles that mention a CVE ID that affects a product developed by Charlesproxy — matched by CVE ID, not by vendor name.