CVE Tools

Central Dogma

7 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Central Dogma, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

Central Dogma CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Central Dogma CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-063
2026-070
2026-080
2026-090

Severity

How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical125%
  • High125%
  • Medium250%

Latest CVEs

The 7 most recently published vulnerabilities affecting Central Dogma.

  1. CVE-2026-11748A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter w...—
  2. CVE-2026-11746A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back ...—
  3. CVE-2026-11745A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing...—
  4. CVE-2025-11222Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing ...6.1
  5. CVE-2024-1143Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.9.3
  6. CVE-2021-38388Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.8.8
  7. CVE-2019-6002Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store