Mnapoli maintains Bref, a PHP runtime and framework for serverless deployment on AWS Lambda that bridges traditional PHP application patterns with event-driven cloud execution. The vendor's disclosed vulnerabilities center on weaknesses in resource interpretation and control—including parsing ambiguities, uncontrolled resource consumption, and insufficient allocation limits—that reflect the constraints and configuration complexity of translating stateless serverless semantics to PHP application logic. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mnapoli over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24754CRITICAL Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converte | Feb 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-24753MEDIUM Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it does not handle multiple values headers. If PHP generates a re | Feb 1, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-24752MEDIUM Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converte | Feb 1, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-29186MEDIUM Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to version 2.1.17 is used with the Event-Driven Function runtime and | Mar 22, 2024 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mnapoli.
Media articles that mention a CVE ID that affects a product developed by Mnapoli — matched by CVE ID, not by vendor name.