Ktor

Vendor:

First CVE: Jul 3, 2019 · Active for 7 years

21
Total CVEs
More Total CVEs than 94% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ktor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2019
7 years ago
Most Recent CVE
Mar 12, 2025
502 days ago

CVE Severity & Scoring

Ktor21 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local1 (4.8%)
Network20 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None17 (81.0%)
Unknown0 (0.0%)
Required4 (19.0%)
Privileges Required
Low2 (9.5%)
High2 (9.5%)
None17 (81.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
Oct 2, 20199.828NONO
In JetBrains Ktor before 2.3.5 server certificates were not verified
Oct 9, 20239.127NONO
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
Oct 9, 20239.826NONO
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
Apr 24, 20237.524NONO
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
Nov 9, 20217.524NONO
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allow
Jul 3, 20198.124NONO
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
Aug 12, 20226.121NONO
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
Nov 16, 20206.521NONO
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
Dec 10, 20196.121NONO
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
May 12, 20224.919NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Ktor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.014.90.8%00
1.2.015.30.7%00