Cloud-foundry
38 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.
Cloud-foundry CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-06 | 4 | 0 |
| 2018-07 | 2 | 0 |
| 2018-08 | null or fewer | |
| 2018-09 | 2 | 0 |
| 2018-10 | 4 | 0 |
| 2018-11 | null or fewer | |
| 2018-12 | 3 | 0 |
| 2019-01 | null or fewer | |
| 2019-02 | 1 | 0 |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | 2 | 0 |
| 2019-08 | 3 | 0 |
| 2019-09 | 3 | 0 |
| 2019-10 | 2 | 0 |
| 2019-11 | 2 | 0 |
| 2019-12 | 2 | 0 |
| 2020-01 | null or fewer | |
| 2020-02 | 4 | 0 |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | 2 | 0 |
| 2020-09 | 2 | 0 |
Products
The products that kept showing up in Cloud-foundry's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cloud-foundry.
- CVE-2026-41012BOSH vSphere CPI Improper Cert Validation7.7
- CVE-2026-59335Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise8.7
- CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass9.0
- CVE-2026-41704Compromised VM can make arbitrary blobstore deletes5.0
- CVE-2026-41009Local Blobstore may allow arbitrary reads/deletes5.8
- CVE-2026-22734Cloud Foundry UAA SAML 2.0 Signature Bypass8.6
- CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
- CVE-2025-22216CVE-2025-22216 UAA Missing Zone Validation5.4
- CVE-2024-38826CVE-2024-38826 Cloud Controller Denial of Service Attack—
- CVE-2024-37082When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundr...9.1
- CVE-2024-22279GoRouter Denial of Service Attack5.9
- CVE-2023-34061CVE-2023-34061 – Gorouter route pruning7.5
- CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter5.3
- CVE-2023-20885CF workflows leak credentials in system audit logs6.5
- CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing7.5
The record
- Peak rank
- #82 in Feb 2020
- Busiest month shown
- Jun 2018, 4 CVEs
- Months with a KEV entry
- 0 since Jun 2018
- Monthly snapshots
- 15 since 2018