CVE Tools

Developer Tools & CI/CD

8,493 CVEs tracked since 1999. In the last 12 months, 1,890, +137% on the 12 before.

Developer Tools & CI/CD by subsector, Sep 2026 so far

Sep 2026 so far: 232 CVEs across 6 subsectors. Area is each subsector's share; inside are the products it counted most. Point at one to read it.
  • CI/CD12353% · 15 vendors
  • IDEs & editors4118% · 6 vendors
  • Build & test tools2511% · 14 vendors
  • Not yet sub-classified24The tagger has not placed these yet
  • Source control115% · 5 vendors
  • Artifact registries83% · 5 vendors

Month by month

Every monthly snapshot of Developer Tools & CI/CD. A column is the CVEs published that month.

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Developer Tools & CI/CD CVEs per month
MonthCVEs
2021-0927
2021-1085
2021-1193
2021-1255
2022-0154
2022-02132
2022-03112
2022-04122
2022-05102
2022-06126
2022-07105
2022-0863
2022-09124
2022-10107
2022-1178
2022-1259
2023-01112
2023-0245
2023-030
2023-0479
2023-05108
2023-0661
2023-07102
2023-0890
2023-09104
2023-1056
2023-1137
2023-1288
2024-0151
2024-0263
2024-0375
2024-0436
2024-0573
2024-0650
2024-0777
2024-0849
2024-0961
2024-1066
2024-1158
2024-1251
2025-0166
2025-0253
2025-0380
2025-0464
2025-0565
2025-0664
2025-07103
2025-0868
2025-0976
2025-1088
2025-1155
2025-12106
2026-01100
2026-0296
2026-0397
2026-04171
2026-05223
2026-06240
2026-07285
2026-08353
2026-09232

Vendors

Who shipped the most Developer Tools & CI/CD CVEs in Sep 2026 so far, with their rank across all vendors.

  1. Jenkins53#17
  2. Jetbrains29#36
  3. GitLab17#67

Weaknesses

The weakness classes behind Developer Tools & CI/CD CVEs in Sep 2026 so far.

  1. CWE-862 Missing Authorization28
  2. CWE-863 Incorrect Authorization22
  3. CWE-79 XSS19
  4. CWE-22 Path Traversal16
  5. CWE-639 Auth Bypass via User Key13
  6. CWE-125 Out-of-bounds Read10

Latest CVEs

The 15 most recently published vulnerabilities in Developer Tools & CI/CD.

  1. CVE-2026-100689GitPython before 3.1.62 Path Traversal via gitmodules path5.9
  2. CVE-2026-100419gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink7.0
  3. CVE-2026-87722Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review—
  4. CVE-2026-87721Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review—
  5. CVE-2026-87720Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suffixes in Gerrit Code Review—
  6. CVE-2026-95985Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces8.8
  7. CVE-2026-58008Unchecked HKDF key-size input in EL3 causes a stack buffer overflow8.1
  8. CVE-2026-58007Unchecked SDM mailbox response address enables EL3 secure-memory corruption8.1
  9. CVE-2026-58006Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memory Corruption8.1
  10. CVE-2026-58005Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3.8.1
  11. CVE-2026-58004Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware.8.1
  12. CVE-2026-13467Systemic Missing Address Validation in SiP SMC Handlers8.1
  13. CVE-2026-13466Unit Confusion in VAB Authentication8.1
  14. CVE-2026-13465EL3 Stack Buffer Overflow in FCS HKDF Request8.1
  15. CVE-2026-90959Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft8.1

The record

Busiest month
Aug 2026, 353 CVEs
Sep 2026 so far
232 CVEs from 48 vendors
Deployment
On-prem, 71%
Monthly snapshots
251 since 1999
All 15 sectors on one map

Is your business exposed to threats like these?

Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.

Request an assessment

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store