Chendotjs develops the Lotos web server, a narrowly scoped product with a small vulnerability footprint in the broader landscape. The observed exposure centers on memory-safety issues, specifically use-after-free conditions that arise in the server's request handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chendotjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22088CRITICAL Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled. | Jan 5, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-24263HIGH Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c. | Feb 5, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chendotjs.
Media articles that mention a CVE ID that affects a product developed by Chendotjs — matched by CVE ID, not by vendor name.