VYPR
Vendor

Cloudflare

Products
35
CVEs
70
Across products
92
Status
Private

Products

35
View all 35 products →

Recent CVEs

70
View all 70 CVEs →
  • CVE-2022-4428HigJan 11, 2023
    risk 0.58cvss 8.9epss 0.01

    support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option. An attacker with access to the local…

  • CVE-2026-11325HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose…

  • CVE-2026-1229CriFeb 24, 2026
    risk 0.57cvss 9.8epss 0.00

    The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3…

  • CVE-2026-0933CriJan 20, 2026
    risk 0.57cvss 9.9epss 0.01

    SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with…

  • CVE-2025-4144CriMay 1, 2025
    risk 0.57cvss 9.8epss 0.01

    PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: …

  • CVE-2014-125026CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

  • CVE-2023-3036HigJun 14, 2023
    risk 0.56cvss 8.6epss 0.02

    An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cfnts/commit/783490b913f05e508a492cd7b02e3c4ec2297b71  enabled a remote attacker to trigger a panic by sending an NTSAuthenticator packet with extension length…

  • CVE-2024-0212HigJan 29, 2024
    risk 0.53cvss 8.1epss 0.01

    The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.

  • CVE-2022-2225HigJul 26, 2022
    risk 0.53cvss 8.1epss 0.00

    By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.

  • CVE-2026-2835CriMar 5, 2026
    risk 0.52cvss 9.1epss 0.01

    An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding…

  • CVE-2026-2833CriMar 5, 2026
    risk 0.52cvss 9.1epss 0.01

    An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the rest of the bytes on the connection to a…

  • CVE-2025-6087CriJun 16, 2025
    risk 0.52cvss 9.1epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary remote content via the…

  • CVE-2026-12523HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each…

  • CVE-2025-4821HigJun 18, 2025
    risk 0.49cvss 7.5epss 0.01

    Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a…

  • CVE-2021-3978HigJan 29, 2025
    risk 0.49cvss 7.5epss 0.00

    When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow…

  • CVE-2023-4241HigAug 16, 2023
    risk 0.49cvss 7.5epss 0.01

    lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

  • CVE-2023-7080HigDec 29, 2023
    risk 0.48cvss 8.5epss 0.01

    The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an attacker on the local network to connect to the inspector and…

  • CVE-2023-2754HigAug 3, 2023
    risk 0.48cvss 7.4epss 0.01

    The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS queries in a secure manner, however, if a user is connected to WARP over an IPv6-capable network, te WARP client did not assign…

  • CVE-2023-1862HigJun 20, 2023
    risk 0.48cvss 7.3epss 0.01

    Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IPC Named Pipe. This would have enabled an attacker to trigger WARP connect and disconnect commands,…

  • CVE-2026-2836HigMar 5, 2026
    risk 0.46cvss 8.1epss 0.00

    A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host…