Cloudfoundry
55 CVEs tracked since 2016. Since Sep 2016, none of them reached CISA KEV.
Cloudfoundry CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2016-09 | 4 | 0 |
| 2016-10 | null or fewer | |
| 2016-11 | null or fewer | |
| 2016-12 | 1 | 0 |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | null or fewer | |
| 2017-04 | null or fewer | |
| 2017-05 | 9 | 0 |
| 2017-06 | null or fewer | |
| 2017-07 | 5 | 0 |
| 2017-08 | 2 | 0 |
| 2017-09 | null or fewer | |
| 2017-10 | 6 | 0 |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | null or fewer | |
| 2018-02 | null or fewer | |
| 2018-03 | 7 | 0 |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | 3 | 0 |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | null or fewer | |
| 2019-01 | null or fewer | |
| 2019-02 | 1 | 0 |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | null or fewer | |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | 3 | 0 |
| 2019-10 | 2 | 0 |
| 2019-11 | 2 | 0 |
| 2019-12 | 2 | 0 |
| 2020-01 | null or fewer | |
| 2020-02 | 4 | 0 |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | 2 | 0 |
| 2020-09 | 2 | 0 |
Products
The products that kept showing up in Cloudfoundry's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cloudfoundry.
- CVE-2026-47829Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director7.8
- CVE-2026-47828Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution via Man-in-the-Middle Credential Replay8.8
- CVE-2026-47826blobs.yaml Path Traversal Allows File Writes9.1
- CVE-2026-41857BOSH CLI Shell Injection7.8
- CVE-2026-22726Route Services Firewall Bypass5.0
- CVE-2026-22727Cloud Foundry unprotected internal endpoints7.5
- CVE-2026-22723UAA User Token Revocation logic error6.5
- CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
- CVE-2024-22279GoRouter Denial of Service Attack5.9
- CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter5.3
- CVE-2023-20882In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right ci...5.9
- CVE-2023-20881Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate u...8.1
- CVE-2023-20903This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to ...4.3
- CVE-2022-31733Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without...9.1
- CVE-2018-25046Path traversal in code.cloudfoundry.org/archiver9.1
The record
- Peak rank
- #36 in Sep 2016
- Busiest month shown
- May 2017, 9 CVEs
- Months with a KEV entry
- 0 since Sep 2016
- Monthly snapshots
- 16 since 2016