http_server
14 known vulnerabilities · 0 critical · 2 high
browserstack-runner has an unauthenticated arbitrary file read via path traversal in HTTP server
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
OpenCode's Unauthenticated HTTP Server Allows Arbitrary Command Execution
@adonisjs/http-server has an Open Redirect vulnerability
Malicious code in @gameforge/http-server (npm)
Path Traversal in angular-http-server
Malicious code in raise-http-server (npm)
engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)