rdiffweb vulnerabilities
CVEs whose affected-version data names the rdiffweb package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-67796High· 8.1IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
▾ Twilightrdiffweb · rdiffwebEPSS 0.24%via OSV
CVE-2023-4138Medium· 4.2RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
▾ Sunlitrdiffweb · rdiffwebEPSS 0.45%via OSV
CVE-2022-3290High· 7.5rdiffweb's unlimited username field length can lead to DoS
rdiffweb's unlimited username field length can lead to DoS
▾ Twilightrdiffweb · rdiffwebEPSS 0.77%via OSV