req
Hex2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting reqpage 1 of 1
- CVE-2026-49755HIGHCVSS 8.2EG 8.2✓ Fixed in 0.6.12026-06-08
vulnerable: 0.1.0 ... 0.6.0 (54 versions)
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb response bodies. Req's default response pipe…
- CVE-2026-49756LOWCVSS 2.1EG 2.1✓ Fixed in 0.6.02026-06-08
vulnerable: 0.5.10 ... 0.5.9 (16 versions)
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part …
Check whether req is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for req CVEs against the assets you own.
Start Free Scan →