Chef
1 CVEs tracked since 2016. Since Jun 2016, none of them reached CISA KEV.
Chef CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2016-06 | 1 | 0 |
Products
The products that kept showing up in Chef's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Chef.
- CVE-2025-8868Chef Automate compliance service SQL Injection Vulnerability9.8
- CVE-2025-6724Chef Automate SQL Injection Vulnerability8.8
- CVE-2023-42658InSpec Archive Command Vulnerable to Maliciously Crafted Profile8.8
- CVE-2023-40050Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application9.9
- CVE-2015-8559The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.7.5
- CVE-2016-4326The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.9.8
The record
- Peak rank
- #88 in Jun 2016
- Busiest month shown
- Jun 2016, 1 CVEs
- Months with a KEV entry
- 0 since Jun 2016
- Monthly snapshots
- 1 since 2016