CVE Tools

Cloud-foundry

38 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.

Cloud-foundry CVEs per month

Jun 2018 to Sep 2020. Point at a month, or focus the strip and use the arrow keys.
Cloud-foundry CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0640
2018-0720
2018-08null or fewer
2018-0920
2018-1040
2018-11null or fewer
2018-1230
2019-01null or fewer
2019-0210
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-0720
2019-0830
2019-0930
2019-1020
2019-1120
2019-1220
2020-01null or fewer
2020-0240
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-0820
2020-0920

Products

The products that kept showing up in Cloud-foundry's monthly top three, with their CVEs summed over those months.

  1. Cf Deployment74 months
  2. Uaa Release (Oss)63 months
  3. Capi44 months
  4. Routing44 months
  5. Uaa Release33 months
  6. Cloud Foundry Uaa22 months
  7. Loggregator21 month
  8. Bits Service11 month
  9. Bits Service Release11 month
  10. Bosh11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cloud-foundry.

  1. CVE-2026-41012BOSH vSphere CPI Improper Cert Validation7.7
  2. CVE-2026-59335Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise8.7
  3. CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass9.0
  4. CVE-2026-41704Compromised VM can make arbitrary blobstore deletes5.0
  5. CVE-2026-41009Local Blobstore may allow arbitrary reads/deletes5.8
  6. CVE-2026-22734Cloud Foundry UAA SAML 2.0 Signature Bypass8.6
  7. CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
  8. CVE-2025-22216CVE-2025-22216 UAA Missing Zone Validation5.4
  9. CVE-2024-38826CVE-2024-38826 Cloud Controller Denial of Service Attack—
  10. CVE-2024-37082When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundr...9.1
  11. CVE-2024-22279GoRouter Denial of Service Attack5.9
  12. CVE-2023-34061CVE-2023-34061 – Gorouter route pruning7.5
  13. CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter5.3
  14. CVE-2023-20885CF workflows leak credentials in system audit logs6.5
  15. CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing7.5

The record

Peak rank
#82 in Feb 2020
Busiest month shown
Jun 2018, 4 CVEs
Months with a KEV entry
0 since Jun 2018
Monthly snapshots
15 since 2018
Cloud-foundry's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store