req vulnerabilities
CVEs whose affected-version data names the req package (erlang). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-49755HighReq vulnerable to unbounded archive/compression extraction triggered by response content-type
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
▾ Twilightreq · reqEPSS 0.60%via GHSA
CVE-2026-49756MediumReq vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
▾ Sunlitreq · reqEPSS 0.21%via GHSA