Search CVE reports


Toggle filters

1 – 9 of 9 results


CVE-2026-32240

Medium priority

Some fixes available 5 of 6

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In...

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-32239

Medium priority

Some fixes available 5 of 6

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could...

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-48230

Medium priority
Ignored

Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket compression enabled, a buffer underrun can be caused by a remote peer. The underrun...

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-46149

Low priority
Vulnerable

Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementation prior to 0.13.7, 0.14.11, and...

2 affected packages

interchange, capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
interchange Not in release Not in release Not in release
capnproto Not affected Not affected Ignored Ignored Ignored
Show less packages

CVE-2015-2313

Medium priority

Some fixes available 1 of 2

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message,...

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Not affected
Show less packages

CVE-2015-2312

Medium priority

Some fixes available 1 of 2

Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a large number of elements.

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Not affected
Show less packages

CVE-2015-2311

Medium priority

Some fixes available 1 of 2

Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execute arbitrary code via a crafted message.

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Not affected
Show less packages

CVE-2015-2310

Medium priority

Some fixes available 1 of 2

Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive information from memory via a crafted message, related...

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Not affected
Show less packages

CVE-2017-7892

Low priority

Some fixes available 3 of 6

Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap'n Proto relies on pointer arithmetic calculations...

1 affected package

capnproto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
capnproto Fixed
Show less packages