CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “linecorp”

88 vulnerabilities found for “linecorp”

Page 1 of 5

CVE-2025-11222
MEDIUM6.1

Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft.

linecorp / central_dogma
Network
Published Dec 4, 2025
Page 1 of 5
CVE-2024-1735
CRITICAL9.1

A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later.

linecorp / armeria
Network
Published Feb 26, 2024
CVE-2024-1143
CRITICAL9.3

Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

linecorp / central_dogma
Network
Published Feb 2, 2024
CVE-2023-39737
HIGH8.2

The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / matsuya
Network
Published Oct 25, 2023
CVE-2023-39736
HIGH8.2

The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / fukunaga_memberscard
Network
Published Oct 25, 2023
CVE-2023-39740
HIGH8.2

The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / onigiriya-musubee
Network
Published Oct 25, 2023
CVE-2023-39735
HIGH8.2

The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / uomasa_saiji_new
Network
Published Oct 25, 2023
CVE-2023-39734
HIGH8.2

The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / trackdiner10\/10_mc
Network
Published Oct 25, 2023
CVE-2023-39732
HIGH8.2

The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / tokueimaru_waiting
Network
Published Oct 25, 2023
CVE-2023-39733
HIGH8.2

The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

linecorp / tonton-tei
Network
Published Oct 25, 2023
CVE-2023-44487
HIGH7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

ietf / http+291
Network
Published Oct 10, 2023
CVE-2023-38493
HIGH7.5

Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might not invoked because of the matrix variables. If an attacker sends a specially crafted request, the request may bypass the authorizer. Version 1.24.3 contains a patch for this issue.

linecorp / armeria
Network
Published Jul 25, 2023
CVE-2021-43795
HIGH7.5

Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.

linecorp / armeria
Network
Published Dec 2, 2021
CVE-2021-41011
HIGH7.5

LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.

linecorp / line
Network
Published Sep 22, 2021
CVE-2021-38388
HIGH8.8

Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.

linecorp / central_dogma
Network
Published Sep 8, 2021
CVE-2021-36215
MEDIUM5.3

LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.

linecorp / line
Network
Published Sep 8, 2021
CVE-2021-36216
HIGH7.8

LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.

linecorp / line
Local
Published Sep 8, 2021
CVE-2021-36214
MEDIUM6.1

LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.

linecorp / line
Network
Published Jul 13, 2021
CVE-2019-16771
MEDIUM4.8

Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.

linecorp / armeria
Network
Published Dec 6, 2019
CVE-2018-0650
HIGH7.4

The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

linecorp / line_music
Network
Published Sep 7, 2018