Cf Deployment
16 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Cf Deployment, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Cf Deployment CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 1 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 4 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High8
- Medium5
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Cf Deployment.
- CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass9.0
- CVE-2026-40965Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed t...10.0
- CVE-2026-40964Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and ...7.5
- CVE-2026-41013Tenant-controlled comma smuggles arbitrary CIFS mount options8.1
- CVE-2026-22726Route Services Firewall Bypass5.0
- CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
- CVE-2023-34061CVE-2023-34061 – Gorouter route pruning7.5
- CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter5.3
- CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing7.5
- CVE-2020-5420Gorouter is vulnerable to DoS attack via invalid HTTP responses7.7
- CVE-2020-5418Cloud Controller allows users with no roles to list droplets4.3
- CVE-2020-5417Cloud Controller may allow developers to claim sensitive routes8.8
- CVE-2020-5416CF clusters with NGINX in front of them may be vulnerable to DoS6.5
- CVE-2019-11283Password leak in smbdriver logs8.8
- CVE-2019-11282UAA is vulnerable to a Blind SCIM injection leading to information disclosure4.3
Product grouping is registry-driven, with AI assist and human review. How it works