ReactPHP is an event-driven, asynchronous PHP library commonly embedded in web services and application frameworks, where its HTTP and networking components present an integration-wide attack surface through inherited dependencies. Observed weakness classes center on input-handling and resource-management issues—including improper input validation, insufficient cookie integrity checking, and uncontrolled resource consumption—that are characteristic of stream-processing and protocol-parsing code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reactphp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26044MEDIUM react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component contain a potential DoS vulnerab | May 17, 2023 | 5.3 | 19 | NO | NO |
CVE-2022-36032MEDIUM ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component versions starting with 0.7.0 and prior to 1.7.0, when ReactPHP | Sep 6, 2022 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reactphp.
Media articles that mention a CVE ID that affects a product developed by Reactphp — matched by CVE ID, not by vendor name.