Security: pocoproject/poco
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Zip ZIP64 parsing: unbounded allocation and heap over-readGHSA-734q-56c6-xp96 published
Sep 22, 2026 by matejkModerate -
URIStreamOpener follows cross-scheme HTTP to file redirects (local file read)GHSA-pqw3-rjcp-v354 published
Sep 22, 2026 by matejkHigh -
JSON parser truncates object keys at embedded NULGHSA-f6vm-f3m6-6v9r published
Sep 22, 2026 by matejkLow -
POCO HTTP server request-boundary differentials (request smuggling primitives)GHSA-p4j9-25v2-pp68 published
Sep 22, 2026 by matejkModerate -
SSLManager config default disables TLS hostname verificationGHSA-xmgr-9wvg-r67x published
Sep 22, 2026 by matejkHigh -
FTPSClientSession downgrades to plaintext when AUTH TLS/SSL rejectedGHSA-gjfc-f6f9-rxx6 published
Sep 22, 2026 by matejkModerate -
NetSSL OCSP stapling accepts response from substituted issuerGHSA-8gjp-96jp-4wh9 published
Sep 22, 2026 by matejkModerate -
Path traversal in SevenZip archive extraction (ZipSlip)GHSA-rcrh-846h-22hx published
Sep 22, 2026 by matejkHigh -
HTTPReactorServer Incomplete-Request Buffer Memory ExhaustionGHSA-2pm5-6f5q-c76r published
Sep 22, 2026 by matejkHigh -
Incorrect comment stripping in POCO JSON parser allows field removal and JSON structure manipulation when comments are enabledGHSA-7frw-wjhr-x6g8 published
Sep 22, 2026 by matejkModerate
Learn more about advisories related to pocoproject/poco in the GitHub Advisory Database