Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Crowcpp

First CVE: Jan 13, 2022Active for: 5 yearsTotal CVEs: 6

Crowcpp maintains the Crow C++ web framework, a lightweight HTTP server library embedded across application-server and microservice implementations. The vendor's vulnerability profile concentrates on a narrow product scope but skews strongly toward critical-severity outcomes, driven by recurring input-handling and output-encoding weaknesses including path traversal, HTTP request/response splitting, cross-site scripting, and injection flaws that are endemic to web-facing request handlers. Defenders should treat patches for this framework as priority updates where Crow is deployed; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Crowcpp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2022
4 years ago
Most Recent CVE
Sep 12, 2023
1,046 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-38667CRITICAL
HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but th
Aug 22, 20229.831NONO
CVE-2022-34970CRITICAL
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute a
Aug 4, 20229.830NONO
CVE-2022-38668HIGH
HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller th
Aug 22, 20227.525NONO
CVE-2021-23514HIGH
This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server.
Jan 13, 20227.525NONO
CVE-2021-23824MEDIUM
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potential
Jan 13, 20226.121NONO
CVE-2023-26142MEDIUM
All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized agains
Sep 12, 20236.117NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Crowcpp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Crowcpp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Crowcpp's Products

View all 2 CNAs →

Top CWEs