Linecorp maintains a modestly sized but prominent portfolio spanning messaging, communication platforms, and open-source infrastructure libraries such as Armeria and Central Dogma, with a significant installed base across consumer and enterprise deployments. The vendor's vulnerability disclosures cluster around application-layer and cryptographic weaknesses—spanning sensitive-information exposure, inadequate encryption strength, cross-site scripting, and authentication flaws—that are characteristic of web-connected and data-handling systems. These weakness classes reflect recurring challenges in input validation, session management, and data protection across the vendor's integrated platform. Defenders should monitor this vendor's advisories closely given the broad reach of its messaging and collaboration products and prioritize patches affecting authentication and encryption mechanisms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linecorp over time
Signals from CVEs in this vendor scope (93 CVEs).
93 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2023-5554CRITICAL Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0. | Oct 12, 2023 | 9.8 | 28 | NO | NO |
CVE-2021-38388HIGH Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. | Sep 8, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-6007HIGH Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors. | Sep 12, 2019 | 8.8 | 27 | NO | NO |
CVE-2026-3861MEDIUM LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insuffic | Apr 16, 2026 | 6.5 | 26 | NO | NO |
CVE-2022-29505HIGH Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation. | Apr 27, 2022 | 7.8 | 26 | NO | NO |
CVE-2016-4850HIGH LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code. | Apr 20, 2017 | 8.1 | 26 | NO | NO |
CVE-2023-45559HIGH An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | Jan 3, 2024 | 8.2 | 25 | NO | NO |
CVE-2023-43300HIGH An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | Dec 7, 2023 | 8.2 | 25 | NO | NO |
CVE-2022-41568HIGH LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. | Nov 29, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (93 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linecorp.
Media articles that mention a CVE ID that affects a product developed by Linecorp — matched by CVE ID, not by vendor name.