CVE Tools

Cloud-foundry-foundation

10 CVEs tracked since 2017. Since Oct 2017, none of them reached CISA KEV.

Cloud-foundry-foundation CVEs per month

Oct 2017 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Cloud-foundry-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-1020
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-0680

Products

The products that kept showing up in Cloud-foundry-foundation's monthly top three, with their CVEs summed over those months.

  1. Bosh31 month
  2. Cf Deployment21 month
  3. Bpm-release11 month
  4. Cloud Foundry Runtime Cf-release11 month
  5. Elastic Runtime11 month
  6. Pivotal Cloud Foundry Elastic Runtime11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cloud-foundry-foundation.

  1. CVE-2026-47839Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin—
  2. CVE-2026-47827CVE-2026-47827 – BOSH CLI Powershell Injection7.5
  3. CVE-2026-47831Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force Attacks7.5
  4. CVE-2026-47830Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable Overwrite8.8
  5. CVE-2026-47833setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary...6.1
  6. CVE-2026-41010ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim fr...8.2
  7. CVE-2026-41011PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the up...8.2
  8. CVE-2026-41858Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a...7.5
  9. CVE-2026-41859A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into ...7.8
  10. CVE-2026-41860CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-...8.8
  11. CVE-2026-40965Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed t...10.0
  12. CVE-2026-40964Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and ...7.5
  13. CVE-2026-41704Compromised VM can make arbitrary blobstore deletes5.0
  14. CVE-2026-41009Local Blobstore may allow arbitrary reads/deletes5.8
  15. CVE-2024-37082When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundr...9.1

The record

Peak rank
#143 in Oct 2017
Busiest month shown
Jun 2026, 8 CVEs
Months with a KEV entry
0 since Oct 2017
Monthly snapshots
2 since 2017
Cloud-foundry-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store