Dart's vulnerability footprint spans a modestly represented collection of development tools and runtime components, including the Dart SDK, compression utilities, and networking libraries that see deployment across web and application-development contexts. The recurring weakness classes center on memory-safety boundaries, input validation in web contexts, and access control—including buffer-boundary violations, cross-site scripting, and authentication-bypass patterns—and vulnerabilities have an elevated tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dart over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4652HIGH Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey | Oct 22, 2008 | 9.3 | 37 | NO | YES |
CVE-2007-2856HIGH Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers | May 24, 2007 | 9.3 | 36 | NO | YES |
CVE-2022-3095CRITICAL The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC | Oct 27, 2022 | 9.8 | 30 | NO | NO |
CVE-2012-3819MEDIUM Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial o | Oct 4, 2012 | 5.0 | 29 | NO | YES |
CVE-2012-5389HIGH NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request. | Jan 23, 2020 | 7.5 | 28 | NO | NO |
CVE-2021-22568HIGH When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publi | Dec 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2026-27704HIGH The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41 | Feb 25, 2026 | 7.5 | 25 | NO | NO |
CVE-2007-2855HIGH Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via | May 24, 2007 | 9.3 | 24 | NO | NO |
CVE-2022-0451MEDIUM Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensi | Feb 18, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-35669MEDIUM An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF i | Dec 24, 2020 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dart.
Media articles that mention a CVE ID that affects a product developed by Dart — matched by CVE ID, not by vendor name.