VendorsJetBrainsktorall versions
Vulnerabilities

JetBrains Ktor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2019-12736
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
Published 2019-10-02 · Modified
9.8EPSS 0.022
CVE-2023-45612
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
Published 2023-10-09 · Modified
9.8EPSS 0.006
CVE-2023-45613
In JetBrains Ktor before 2.3.5 server certificates were not verified
Published 2023-10-09 · Modified
9.1EPSS 0.003
CVE-2022-29930
SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.
Published 2022-05-12 · Modified
8.7EPSS 0.009
CVE-2019-10102
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.
Published 2019-07-03 · Modified
8.1EPSS 0.008
CVE-2021-43203
In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
Published 2021-11-09 · Modified
7.5EPSS 0.009
CVE-2020-5207
Request smuggling is possible in Ktor when both chunked TE and content length specified
Published 2020-01-27 · Modified
7.5EPSS 0.008
CVE-2022-48476
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
Published 2023-04-24 · Modified
7.5EPSS 0.008
CVE-2020-26129
In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.
Published 2020-11-16 · Modified
6.5EPSS 0.008
CVE-2022-38180
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
Published 2022-08-12 · Modified
6.5EPSS 0.007
CVE-2019-19703
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
Published 2019-12-10 · Modified
6.1EPSS 0.006
CVE-2022-38179
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
Published 2022-08-12 · Modified
6.1EPSS 0.005
CVE-2019-19389
JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting.
Published 2019-12-26 · Modified
5.4EPSS 0.008
CVE-2021-25762
In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.
Published 2021-02-03 · Modified
5.3EPSS 0.008
CVE-2019-12737
UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
Published 2019-10-02 · Modified
5.3EPSS 0.007
CVE-2021-25763
In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.
Published 2021-02-03 · Modified
5.3EPSS 0.005
CVE-2021-25761
In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.
Published 2021-02-03 · Modified
5.3EPSS 0.005
CVE-2024-49580
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
Published 2024-10-17 · Modified
5.3EPSS 0.004
CVE-2025-29904
In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible
Published 2025-03-12 · Analyzed
5.3EPSS 0.003
CVE-2022-29035
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
Published 2022-04-11 · Modified
4.0EPSS 0.006
CVE-2023-34339
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
Published 2023-06-01 · Modified
3.3EPSS 0.002