Cometd is a messaging and real-time communication framework primarily represented by its core product, a library focused on bidirectional server-client interaction over HTTP and WebSocket protocols. The observed vulnerability pattern centers on incorrect authorization logic, a recurring weakness class that reflects the authentication and access-control challenges inherent to real-time communication architectures where multiple clients and channels share message state.
The number and severity of CVEs published that impact products developed by Cometd over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24721HIGH CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channels is improperly authorized, so | Mar 15, 2022 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cometd.
Media articles that mention a CVE ID that affects a product developed by Cometd — matched by CVE ID, not by vendor name.