Paranoidhttp Project maintains a narrowly scoped HTTP client library focused on mitigating server-side request forgery and related network-layer attack vectors. The recurring weakness class associated with this vendor reflects the inherent complexity of safely validating and constraining outbound HTTP requests in untrusted environments.
The number and severity of CVEs published that impact products developed by Paranoidhttp Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24623HIGH Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses. | Jan 30, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paranoidhttp Project.
Media articles that mention a CVE ID that affects a product developed by Paranoidhttp Project — matched by CVE ID, not by vendor name.