Groonga is a full-text search engine and indexing library primarily exposed through its HTTP daemon interface, which serves as the operational entry point for search and data-retrieval operations. The observed vulnerability pattern centers on race conditions in concurrent resource access within the HTTP daemon, a weakness class inherent to multi-threaded server architectures handling simultaneous client requests. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Groonga over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11675HIGH The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interactio | May 2, 2019 | 7.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Groonga.
Media articles that mention a CVE ID that affects a product developed by Groonga — matched by CVE ID, not by vendor name.