Critical severity9.1NVD Advisory· Published Apr 18, 2025· Updated Jun 17, 2026
CVE-2024-29643
CVE-2024-29643
Description
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
croogo/croogoPackagist | <= 3.0.2 | — |
Affected products
2Patches
Vulnerability mechanics
References
4- medium.com/@christbowel6/cve-2024-29643-host-header-injection-in-croogo-v3-0-2-0aded525f574nvdExploitPress/Media CoverageWEB
- github.com/advisories/GHSA-847x-x4jg-6gf4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-29643ghsaADVISORY
- github.com/croogo/croogo/issues/1005ghsaWEB
News mentions
0No linked articles in our index yet.