rdiffweb has 3 CVEs on record between 2022 and 2026. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- rdiffweb 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-67796High· 8.1IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users45CVE-2022-3290High· 7.5rdiffweb's unlimited username field length can lead to DoS41CVE-2023-4138Medium· 4.2RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling23
rdiffweb vulnerabilities
CVEs affecting rdiffweb, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-67796High· 8.1IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
▾ Twilightrdiffweb · rdiffwebEPSS 0.24%via OSV
CVE-2023-4138Medium· 4.2RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
▾ Sunlitrdiffweb · rdiffwebEPSS 0.45%via OSV
CVE-2022-3290High· 7.5rdiffweb's unlimited username field length can lead to DoS
rdiffweb's unlimited username field length can lead to DoS
▾ Twilightrdiffweb · rdiffwebEPSS 0.77%via OSV