← Back

Jooby

jooby

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Jooby
jooby

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jooby
1Jooby
Jun 17, 2026
May 11, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
All versions before 1.6.7 and all versions after 2.0.0 inclusive and before 2.8.2 of io.jooby:jooby and org.jooby:jooby are vulnerable to Directory Traversal via two separate vectors.
1Jooby
1Jooby
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Split...Show more
This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.Show less
1Jooby
1Jooby
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jooby before 1.6.4 has XSS via the default error handler.