{"schema_version":1,"title":"rdiffweb (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 43 vulnerabilities in rdiffweb (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-67796, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/rdiffweb","json_url":"https://junglewise.ai/threats/technologies/rdiffweb.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/rdiffweb","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":43,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":2},"latest":[{"cve":"CVE-2025-67796","cvss":3.1,"epss":0.0025,"slug":"cve-2025-67796-ikus-rdiffweb-allows-an-attacker-with-any-valid-or-stolen-access","title":"PYSEC-2026-3048 - IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users","severity":"low","exploited":false,"published_at":"2026-07-13T15:02:57.24484+00:00","url":"https://junglewise.ai/threats/cve-2025-67796-ikus-rdiffweb-allows-an-attacker-with-any-valid-or-stolen-access"},{"cve":"CVE-2023-4138","cvss":3,"epss":0.0045,"slug":"cve-2023-4138-rdiffweb-vulnerable-to-allocation-of-resources-without-limits-or","title":"PYSEC-2026-1863 - RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:21.664521+00:00","url":"https://junglewise.ai/threats/cve-2023-4138-rdiffweb-vulnerable-to-allocation-of-resources-without-limits-or"},{"cve":"CVE-2023-5289","cvss":3.1,"epss":0.0065,"slug":"cve-2023-5289-rdiffweb-allocation-of-resources-without-limits-or-throttling","title":"PYSEC-2023-186 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.","severity":"low","exploited":false,"published_at":"2023-09-29T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-5289-rdiffweb-allocation-of-resources-without-limits-or-throttling"},{"cve":"CVE-2022-4720","cvss":3.1,"epss":0.0048,"slug":"cve-2022-4720-rdiffweb-vulnerable-to-open-redirect","title":"PYSEC-2022-43006 - Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4720-rdiffweb-vulnerable-to-open-redirect"},{"cve":"CVE-2022-4724","cvss":3.1,"epss":0.0083,"slug":"cve-2022-4724-rdiffweb-improper-access-control-vulnerability","title":"PYSEC-2022-43010 - Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4724-rdiffweb-improper-access-control-vulnerability"},{"cve":"CVE-2022-4719","cvss":3,"epss":0.0098,"slug":"cve-2022-4719-rdiffweb-business-logic-errors","title":"PYSEC-2022-43005 - Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4719-rdiffweb-business-logic-errors"},{"cve":"CVE-2022-4722","cvss":3.1,"epss":0.0113,"slug":"cve-2022-4722-rdiffweb-vulnerable-to-authentication-bypass-by-primary-weakness","title":"PYSEC-2022-43008 - Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4722-rdiffweb-vulnerable-to-authentication-bypass-by-primary-weakness"},{"cve":"CVE-2022-4723","cvss":3.1,"epss":0.0063,"slug":"cve-2022-4723-rdiffweb-has-no-rate-limit-on-resend-email-feature","title":"PYSEC-2022-43009 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4723-rdiffweb-has-no-rate-limit-on-resend-email-feature"},{"cve":"CVE-2022-4721","cvss":3.1,"epss":0.0049,"slug":"cve-2022-4721-rdiffweb-vulnerable-to-special-element-injection","title":"PYSEC-2022-43007 - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4721-rdiffweb-vulnerable-to-special-element-injection"},{"cve":"CVE-2022-4646","cvss":3.1,"epss":0.0032,"slug":"cve-2022-4646-rdiffweb-vulnerable-to-cross-site-request-forgery","title":"PYSEC-2022-43004 - Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.","severity":"low","exploited":false,"published_at":"2022-12-22T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4646-rdiffweb-vulnerable-to-cross-site-request-forgery"},{"cve":"CVE-2022-4644","cvss":3.1,"epss":0.006,"slug":"cve-2022-4644-rdiffweb-open-redirect-vulnerability","title":"PYSEC-2022-43003 - Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.","severity":"low","exploited":false,"published_at":"2022-12-22T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4644-rdiffweb-open-redirect-vulnerability"},{"cve":"CVE-2022-4314","cvss":3.1,"epss":0.0082,"slug":"cve-2022-4314-improper-privilege-management-in-rdiffweb","title":"PYSEC-2022-43002 - Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.","severity":"low","exploited":false,"published_at":"2022-12-12T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4314-improper-privilege-management-in-rdiffweb"},{"cve":"CVE-2022-4018","cvss":3.1,"epss":0.0087,"slug":"cve-2022-4018-rdiffweb-vulnerable-to-missing-authentication-for-critical","title":"PYSEC-2022-43001 - Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.","severity":"low","exploited":false,"published_at":"2022-11-16T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4018-rdiffweb-vulnerable-to-missing-authentication-for-critical"},{"cve":"CVE-2022-3362","cvss":3.1,"epss":0.0094,"slug":"cve-2022-3362-rdiffweb-vulnerable-to-insufficient-session-expiration","title":"PYSEC-2022-43000 - Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.","severity":"low","exploited":false,"published_at":"2022-11-14T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3362-rdiffweb-vulnerable-to-insufficient-session-expiration"},{"cve":"CVE-2022-3363","cvss":3.1,"epss":0.0082,"slug":"cve-2022-3363-rdiffweb-subject-to-business-logic-errors","title":"PYSEC-2022-42978 - Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.","severity":"low","exploited":false,"published_at":"2022-10-26T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3363-rdiffweb-subject-to-business-logic-errors"},{"cve":"CVE-2022-3327","cvss":3.1,"epss":0.0084,"slug":"cve-2022-3327-rdiffweb-is-missing-authentication-for-critical-function","title":"PYSEC-2022-42977 - Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.","severity":"low","exploited":false,"published_at":"2022-10-20T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3327-rdiffweb-is-missing-authentication-for-critical-function"},{"cve":"CVE-2022-3439","cvss":3.1,"epss":0.0068,"slug":"cve-2022-3439-missing-rate-limit-on-rdiffweb","title":"PYSEC-2022-43159 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.","severity":"low","exploited":false,"published_at":"2022-10-14T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3439-missing-rate-limit-on-rdiffweb"},{"cve":"CVE-2022-3456","cvss":3.1,"epss":0.0037,"slug":"cve-2022-3456-missing-rate-limit-on-rdiffweb","title":"PYSEC-2022-43160 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.","severity":"low","exploited":false,"published_at":"2022-10-13T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3456-missing-rate-limit-on-rdiffweb"},{"cve":"CVE-2022-3457","cvss":3.1,"epss":0.0036,"slug":"cve-2022-3457-origin-validation-error-in-rdiffweb","title":"PYSEC-2022-43161 - Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.","severity":"low","exploited":false,"published_at":"2022-10-13T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3457-origin-validation-error-in-rdiffweb"},{"cve":"CVE-2022-3438","cvss":3.1,"epss":0.0055,"slug":"cve-2022-3438-rdiffweb-vulnerable-to-open-redirect","title":"PYSEC-2022-43158 - Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.","severity":"low","exploited":false,"published_at":"2022-10-10T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3438-rdiffweb-vulnerable-to-open-redirect"},{"cve":"CVE-2022-3273","cvss":3.1,"epss":0.0048,"slug":"cve-2022-3273-rdiffweb-does-not-have-a-rate-limit-on-incorrect-password-attempts","title":"PYSEC-2022-43156 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.","severity":"low","exploited":false,"published_at":"2022-10-06T18:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3273-rdiffweb-does-not-have-a-rate-limit-on-incorrect-password-attempts"},{"cve":"CVE-2022-3389","cvss":3.1,"epss":0.0113,"slug":"cve-2022-3389-rdiffweb-path-traversal-vulnerability","title":"PYSEC-2022-302 - Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.","severity":"low","exploited":false,"published_at":"2022-10-06T18:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3389-rdiffweb-path-traversal-vulnerability"},{"cve":"CVE-2022-3376","cvss":3.1,"epss":0.0075,"slug":"cve-2022-3376-rdiffweb-allows-a-new-password-to-be-the-same-as-the-previous","title":"PYSEC-2022-43157 - Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.","severity":"low","exploited":false,"published_at":"2022-10-06T18:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3376-rdiffweb-allows-a-new-password-to-be-the-same-as-the-previous"},{"cve":"CVE-2022-3371","cvss":3.1,"epss":0.011,"slug":"cve-2022-3371-rdiffweb-unvalidated-token-name-length-leads-to-dos","title":"PYSEC-2022-299 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.","severity":"low","exploited":false,"published_at":"2022-09-30T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3371-rdiffweb-unvalidated-token-name-length-leads-to-dos"},{"cve":"CVE-2022-3364","cvss":3,"epss":0.0106,"slug":"cve-2022-3364-rdiffweb-s-unlimited-length-fullname-field-can-lead-to-dos","title":"PYSEC-2022-298 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.","severity":"low","exploited":false,"published_at":"2022-09-29T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3364-rdiffweb-s-unlimited-length-fullname-field-can-lead-to-dos"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"rdiffweb (PyPI)","slug":"rdiffweb","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.ikus-soft.com/en/rdiffweb/","repo_url":"https://github.com/ikus-soft/rdiffweb","description":"A web interface for rdiff-backup repositories.","url":"https://junglewise.ai/threats/technologies/rdiffweb"},"most_severe":[{"cve":"CVE-2022-3290","cvss":7.5,"epss":0.0087,"slug":"cve-2022-3290-rdiffweb-denial-of-service-via-unlimited-username-length","title":"rdiffweb Denial of Service via unlimited username length","severity":"high","exploited":false,"published_at":"2022-09-27T00:00:17+00:00","url":"https://junglewise.ai/threats/cve-2022-3290-rdiffweb-denial-of-service-via-unlimited-username-length"},{"cve":"CVE-2022-3272","cvss":3.1,"epss":0.0177,"slug":"cve-2022-3272-rdiffweb-s-unlimited-length-email-field-can-lead-to-dos","title":"PYSEC-2022-291 - Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.","severity":"low","exploited":false,"published_at":"2022-09-26T17:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3272-rdiffweb-s-unlimited-length-email-field-can-lead-to-dos"},{"cve":"CVE-2022-3167","cvss":3.1,"epss":0.0117,"slug":"cve-2022-3167-rdiffweb-vulnerable-to-improper-restriction-of-rendered-ui-layers","title":"PYSEC-2022-268 - Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.","severity":"low","exploited":false,"published_at":"2022-09-08T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3167-rdiffweb-vulnerable-to-improper-restriction-of-rendered-ui-layers"},{"cve":"CVE-2022-3298","cvss":3.1,"epss":0.0114,"slug":"cve-2022-3298-rdiffweb-vulnerable-to-potential-dos-via-memory-consumption","title":"PYSEC-2022-294 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.","severity":"low","exploited":false,"published_at":"2022-09-26T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3298-rdiffweb-vulnerable-to-potential-dos-via-memory-consumption"},{"cve":"CVE-2022-3295","cvss":3.1,"epss":0.0114,"slug":"cve-2022-3295-rdiffweb-allows-unlimited-length-of-root-directory-name-which","title":"PYSEC-2022-293 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.","severity":"low","exploited":false,"published_at":"2022-09-26T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3295-rdiffweb-allows-unlimited-length-of-root-directory-name-which"},{"cve":"CVE-2022-4722","cvss":3.1,"epss":0.0113,"slug":"cve-2022-4722-rdiffweb-vulnerable-to-authentication-bypass-by-primary-weakness","title":"PYSEC-2022-43008 - Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.","severity":"low","exploited":false,"published_at":"2022-12-27T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-4722-rdiffweb-vulnerable-to-authentication-bypass-by-primary-weakness"},{"cve":"CVE-2022-3389","cvss":3.1,"epss":0.0113,"slug":"cve-2022-3389-rdiffweb-path-traversal-vulnerability","title":"PYSEC-2022-302 - Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.","severity":"low","exploited":false,"published_at":"2022-10-06T18:16:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3389-rdiffweb-path-traversal-vulnerability"},{"cve":"CVE-2022-3371","cvss":3.1,"epss":0.011,"slug":"cve-2022-3371-rdiffweb-unvalidated-token-name-length-leads-to-dos","title":"PYSEC-2022-299 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.","severity":"low","exploited":false,"published_at":"2022-09-30T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3371-rdiffweb-unvalidated-token-name-length-leads-to-dos"},{"cve":"CVE-2022-3179","cvss":3.1,"epss":0.0096,"slug":"cve-2022-3179-rdiffweb-contains-weak-password-requirements","title":"PYSEC-2022-272 - Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.","severity":"low","exploited":false,"published_at":"2022-09-13T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3179-rdiffweb-contains-weak-password-requirements"},{"cve":"CVE-2022-3362","cvss":3.1,"epss":0.0094,"slug":"cve-2022-3362-rdiffweb-vulnerable-to-insufficient-session-expiration","title":"PYSEC-2022-43000 - Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.","severity":"low","exploited":false,"published_at":"2022-11-14T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3362-rdiffweb-vulnerable-to-insufficient-session-expiration"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}