Developer Tools & CI/CD
8,493 CVEs tracked since 1999. In the last 12 months, 1,890, +137% on the 12 before.
Developer Tools & CI/CD by subsector, Sep 2026 so far
- CI/CD12353% · 15 vendors
- IDEs & editors4118% · 6 vendors
- Build & test tools2511% · 14 vendors
- Not yet sub-classified24The tagger has not placed these yet
- Source control115% · 5 vendors
- Artifact registries83% · 5 vendors
Month by month
Every monthly snapshot of Developer Tools & CI/CD. A column is the CVEs published that month.
| Month | CVEs |
|---|---|
| 2021-09 | 27 |
| 2021-10 | 85 |
| 2021-11 | 93 |
| 2021-12 | 55 |
| 2022-01 | 54 |
| 2022-02 | 132 |
| 2022-03 | 112 |
| 2022-04 | 122 |
| 2022-05 | 102 |
| 2022-06 | 126 |
| 2022-07 | 105 |
| 2022-08 | 63 |
| 2022-09 | 124 |
| 2022-10 | 107 |
| 2022-11 | 78 |
| 2022-12 | 59 |
| 2023-01 | 112 |
| 2023-02 | 45 |
| 2023-03 | 0 |
| 2023-04 | 79 |
| 2023-05 | 108 |
| 2023-06 | 61 |
| 2023-07 | 102 |
| 2023-08 | 90 |
| 2023-09 | 104 |
| 2023-10 | 56 |
| 2023-11 | 37 |
| 2023-12 | 88 |
| 2024-01 | 51 |
| 2024-02 | 63 |
| 2024-03 | 75 |
| 2024-04 | 36 |
| 2024-05 | 73 |
| 2024-06 | 50 |
| 2024-07 | 77 |
| 2024-08 | 49 |
| 2024-09 | 61 |
| 2024-10 | 66 |
| 2024-11 | 58 |
| 2024-12 | 51 |
| 2025-01 | 66 |
| 2025-02 | 53 |
| 2025-03 | 80 |
| 2025-04 | 64 |
| 2025-05 | 65 |
| 2025-06 | 64 |
| 2025-07 | 103 |
| 2025-08 | 68 |
| 2025-09 | 76 |
| 2025-10 | 88 |
| 2025-11 | 55 |
| 2025-12 | 106 |
| 2026-01 | 100 |
| 2026-02 | 96 |
| 2026-03 | 97 |
| 2026-04 | 171 |
| 2026-05 | 223 |
| 2026-06 | 240 |
| 2026-07 | 285 |
| 2026-08 | 353 |
| 2026-09 | 232 |
Vendors
Who shipped the most Developer Tools & CI/CD CVEs in Sep 2026 so far, with their rank across all vendors.
Weaknesses
The weakness classes behind Developer Tools & CI/CD CVEs in Sep 2026 so far.
Latest CVEs
The 15 most recently published vulnerabilities in Developer Tools & CI/CD.
- CVE-2026-100689GitPython before 3.1.62 Path Traversal via gitmodules path5.9
- CVE-2026-100419gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink7.0
- CVE-2026-87722Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review—
- CVE-2026-87721Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review—
- CVE-2026-87720Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suffixes in Gerrit Code Review—
- CVE-2026-95985Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces8.8
- CVE-2026-58008Unchecked HKDF key-size input in EL3 causes a stack buffer overflow8.1
- CVE-2026-58007Unchecked SDM mailbox response address enables EL3 secure-memory corruption8.1
- CVE-2026-58006Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memory Corruption8.1
- CVE-2026-58005Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3.8.1
- CVE-2026-58004Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware.8.1
- CVE-2026-13467Systemic Missing Address Validation in SiP SMC Handlers8.1
- CVE-2026-13466Unit Confusion in VAB Authentication8.1
- CVE-2026-13465EL3 Stack Buffer Overflow in FCS HKDF Request8.1
- CVE-2026-90959Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft8.1
The record
- Busiest month
- Aug 2026, 353 CVEs
- Sep 2026 so far
- 232 CVEs from 48 vendors
- Deployment
- On-prem, 71%
- Monthly snapshots
- 251 since 1999
Is your business exposed to threats like these?
Discuss a security assessment of your internet-facing systems. Scope, price and timing agreed before testing.
Request an assessment