{"id":"CVE-2022-34970","details":"Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.","modified":"2026-08-12T13:01:06.556388Z","published":"2022-08-04T18:39:06Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34970.json"},"references":[{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/193.html"},{"type":"WEB","url":"https://github.com/0xhebi/CVE-2022-34970/blob/master/report.md"},{"type":"WEB","url":"https://github.com/CrowCpp/Crow/releases/tag/v1.0%2B4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34970.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34970"},{"type":"FIX","url":"https://github.com/CrowCpp/Crow/pull/486"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/crowcpp/crow","events":[{"introduced":"0"},{"fixed":"62dae4cc32229e372bb81c0a20c19f2727345e71"}],"database_specific":{"cpe":"cpe:2.3:a:crowcpp:crow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0+4"},{"fixed":"1.0\\+4"}],"source":["DESCRIPTION","CPE_RANGE","REFERENCES"]}}],"versions":["v1.0+3","v1.0+2","v1.0+1","v1.0","v0.3","0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-34970.json","vanir_signatures_modified":"2026-08-12T13:01:06Z","vanir_signatures":[{"digest":{"length":657,"function_hash":"336938383434325191902643563944787926562"},"id":"CVE-2022-34970-6073f16d","signature_type":"Function","signature_version":"v1","source":"https://github.com/crowcpp/crow/commit/62dae4cc32229e372bb81c0a20c19f2727345e71","target":{"file":"include/crow/query_string.h","function":"qs_parse"},"deprecated":false},{"target":{"file":"include/crow/query_string.h"},"deprecated":false,"digest":{"line_hashes":["181069325050730614390994020731278716795","102873384906716306407912897727626310214","88213764132756482993718457627673947381","156651280475791468279827093503004407029","169940499544219386184258702819157697858","159203152154726909533663750365906025093","275499987689425730698452471984301144009","278970894955859571642790026944179829431"],"threshold":0.9},"id":"CVE-2022-34970-cfd24717","signature_type":"Line","signature_version":"v1","source":"https://github.com/crowcpp/crow/commit/62dae4cc32229e372bb81c0a20c19f2727345e71"}]}}],"schema_version":"1.9.0"}