Tomphttp is a narrowly scoped vendor whose vulnerability profile centers on its Tomp Bare Server product, with the durable signal focused on HTTP request parsing and interpretation flaws. The recurring weakness class reflects inconsistent handling of ambiguous or edge-case HTTP requests that can lead to request or response smuggling, a class of protocol-level confusion that undermines downstream security controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tomphttp over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27922CRITICAL TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure handling of HTTP requests by the @tomphttp/bare-server-node pac | Mar 21, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tomphttp.
Media articles that mention a CVE ID that affects a product developed by Tomphttp — matched by CVE ID, not by vendor name.