Heroiclabs develops Nakama, a backend-as-a-service platform for multiplayer and social games, with its observed vulnerability exposure centered on authentication and session-management weaknesses such as improper brute-force controls and insufficient session timeout mechanisms. These classes reflect the authentication-layer demands of a service handling user identity and game-state coordination; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Heroiclabs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2321CRITICAL Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks. | Jul 5, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-2306HIGH Old session tokens can be used to authenticate to the application and send authenticated requests. | Jul 5, 2022 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Heroiclabs.
Media articles that mention a CVE ID that affects a product developed by Heroiclabs — matched by CVE ID, not by vendor name.