{"id":"CVE-2020-23622","details":"An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK parameter in the request header","aliases":["GHSA-c438-6f6r-pg8w"],"modified":"2026-07-09T00:13:40.171179Z","published":"2022-08-15T20:15:09.040Z","references":[{"type":"FIX","url":"https://github.com/4thline/cling/issues/253"},{"type":"ARTICLE","url":"https://zh-cn.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of?tns_redirect=true"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/4thline/cling","events":[{"introduced":"5fd60eb9e2e87f2ae6d1cf049145c4187040518c"},{"last_affected":"c1a9b8bf37a36a45b9924902179f9b23950b7340"}],"database_specific":{"cpe":"cpe:2.3:a:cling_project:cling:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.1.2"}],"source":"CPE_RANGE"}}],"versions":["2.1.2","2.1.1","2.1.0","2.0.1","2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23622.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}