rejetto has 4 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 9.9 (critical), with 3 rated critical. Most affected products: hfs2 (3), http_file_server (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 25% vs 1% corpus
- Median CVSS
- 9.9
- Publish → KEV
- —(1)
- Last 90 days
- 3 prev 0
Weakness classes
Products
- hfs2 3
- http_file_server 1
Worst active — by depth score
CVE-2024-23692Critical· 9.8Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability100CVE-2026-97360Critical· 10.0HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …67CVE-2026-97359Critical· 10.0HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename55CVE-2026-97362High· 7.5HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request53
rejetto vulnerabilities
CVEs affecting rejetto, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-97362High· 7.5PoCHFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung ser…
CVE-2026-97359Critical· 10.0HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename
HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attac…
CVE-2026-97360Critical· 10.0PoCHFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …
CVE-2024-23692Critical· 9.8CISA KEVPoCRejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…