Known vulnerabilities in mitmproxy
Vendor:
mitmproxy.org
Software:
mitmproxy
Software CPE:
cpe:2.3:a:mitmproxy.org:mitmproxy:*:*:*:*:*:*:*:*
Website:
https://mitmproxy.org/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
12.2.3
12.2.2
12.2.1
12.2.0
12.1.2
12.1.1
12.1.0
12.0.1
12.0.0
11.1.3
11.1.2
11.1.1
11.1.0
11.0.2
11.0.1
11.0.0
10.4.2
10.4.1
10.4.0
10.3.1
10.3.0
10.2.4
10.2.3
10.2.2
10.2.1
10.2.0
10.1.6
10.1.5
10.1.4
10.1.3
10.1.2
10.1.1
10.1.0
10.0.0
9.0.1
9.0.0
8.1.1
8.1.0
8.0.0
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
6.0.2
6.0.1
6.0.0
5.3.0
5.2
5.1.1
5.1.0
5.0.1
5.0.0
4.0.4
4.0.3
4.0.1
4.0.0
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.0.2
2.0.1
2.0.0
1.0.2
1.0.1
1.0
0.18.3
0.18.2
0.18.1
0.18
0.17.1
0.17
0.16
0.15.1
0.15
0.14
0.13.1
0.13
0.12.1
0.12
0.11.3
0.11.2
0.11.1
0.11
0.10.1
0.10
0.9.2
0.9.1
0.9
0.8.1
0.8
0.7
0.6
0.5
0.4
0.3
0.2.2
0.2.1
0.2
0.1
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125835 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2026-40606 |
CWE-90 | Medium | 12.2.2 | 13.04.2026 |
SB2026041322 |
||
| #VU114414 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-57804 |
CWE-444 | Low | 12.1.2 | 25.08.2025 |
SB2025082558 SB2025091298 SB2025091302 and 2 more |
||
| #VU103685 - Missing Authorization CVE-2025-23217 |
CWE-862 | Low | 11.1.2 | 06.02.2025 |
SB2025020644 |
||
| #VU125834 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-24766 |
CWE-444 | Medium | 8.0.0 | 19.03.2022 |
SB2022031912 |
||
| #VU56667 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-39214 |
CWE-444 | Medium | 7.0.3 | 16.09.2021 |
SB2021091618 |
||
| #VU27048 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
CWE-78 | High | 5.0.0 | 21.04.2020 |
SB2020042122 |