Ithewei develops libhv, a network communication library, where the modest vulnerability profile centers on input-handling and neutralization weaknesses including cross-site scripting, CRLF injection, HTTP request/response splitting, and broader injection flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ithewei over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1867CRITICAL Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows HTTP Response Smuggling.This issue affects libhv: through 1.3 | Mar 3, 2025 | 10.0 | 28 | NO | NO |
CVE-2023-26147MEDIUM All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriag | Sep 29, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-26146MEDIUM All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application | Sep 29, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-26148MEDIUM All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return l | Sep 29, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ithewei.
Media articles that mention a CVE ID that affects a product developed by Ithewei — matched by CVE ID, not by vendor name.