Userver is a niche C++ framework for building high-performance asynchronous web services and microservices, with its vulnerability exposure confined to the framework itself. The observed weakness classes center on resource-consumption issues and cases where vulnerability details remain under-specified, reflecting the parsing and concurrency challenges inherent to an event-driven framework. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Userver over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28229HIGH The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of service via crafted HTTP request, involving collisions. | Dec 23, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Userver.
Media articles that mention a CVE ID that affects a product developed by Userver — matched by CVE ID, not by vendor name.