Request Project maintains the request HTTP client library, a widely embedded utility for server-side HTTP operations across numerous applications and frameworks. The recurring vulnerability pattern centers on input handling and server-side request behavior, with observed weaknesses spanning improper input validation, sensitive-data leakage in transit, and server-side request forgery—issues endemic to a library sitting in the request path between applications and external services. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Request Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28155MEDIUM The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to | Mar 16, 2023 | 6.1 | 21 | NO | NO |
CVE-2017-16026MEDIUM Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This | Jun 4, 2018 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Request Project.
Media articles that mention a CVE ID that affects a product developed by Request Project — matched by CVE ID, not by vendor name.