The Internet Engineering Task Force maintains a body of standards spanning network protocols and cryptographic specifications such as IPv6, 802.1Q, PKCS#1, and Generic Routing Encapsulation, which are foundational to internet infrastructure and widely embedded across operating systems, networking equipment, and security applications. Vulnerabilities identified in IETF standards and protocol implementations recur through authentication-bypass and spoofing flaws, cryptographic weaknesses, and improper handling of length parameters, and such issues frequently acquire public exploit code. Defenders should treat protocol-level flaws in this portfolio as high-impact: remediation often requires coordinated updates across a broad ecosystem of vendors and devices rather than single-point patches, and the widespread embedding of these standards amplifies the consequence of each disclosure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ietf over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2004-2761CRITICAL The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the us | Jan 5, 2009 | 9.8 | 42 | NO | YES |
CVE-2016-10142HIGH An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vend | Jan 14, 2017 | 8.6 | 31 | NO | NO |
CVE-2015-8960HIGH The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the a | Sep 21, 2016 | 8.1 | 27 | NO | NO |
CVE-2018-5389MEDIUM The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross | Sep 6, 2018 | 5.9 | 23 | NO | NO |
CVE-2020-20949MEDIUM Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bl | Jan 20, 2021 | 5.9 | 22 | NO | NO |
CVE-2020-20950MEDIUM Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbach | Jan 19, 2021 | 5.9 | 22 | NO | NO |
CVE-2025-23019MEDIUM IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface. | Jan 14, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-23018MEDIUM IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing an attacker to spoof and route arbitrar | Jan 14, 2025 | 6.5 | 21 | NO | NO |
CVE-2007-2242HIGH The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create network amplification between two route | Apr 25, 2007 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ietf.
Media articles that mention a CVE ID that affects a product developed by Ietf — matched by CVE ID, not by vendor name.