CVE Tools

Palantir

26 CVEs tracked since 2022. Since Nov 2022, none of them reached CISA KEV.

Palantir CVEs per month

Nov 2022 to Aug 2023. Point at a month, or focus the strip and use the arrow keys.
Palantir CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-1140
2022-12null or fewer
2023-01null or fewer
2023-0270
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0660
2023-0750
2023-0840

Products

The products that kept showing up in Palantir's monthly top three, with their CVEs summed over those months.

  1. Com.palantir.foundry:foundry-frontend42 months
  2. Gotham31 month
  3. Foundry Frontend21 month
  4. Clips211 month
  5. Com.palantir.comments:comments11 month
  6. Com.palantir.contour:contour-dispatch11 month
  7. Com.palantir.magritte:magritte-rest-source-bundle11 month
  8. Foundry11 month
  9. Foundry Blobster11 month
  10. Foundry Code-workbooks11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Palantir.

  1. CVE-2025-68609Authentication bypass in Aries due to misconfiguration6.6
  2. CVE-2025-62487Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files.3.5
  3. CVE-2023-30971Gaia unauthenticated endpoints6.8
  4. CVE-2024-49587Glutton V1 endpoints missing authentication9.1
  5. CVE-2025-53710Network boundaries not respected in certain Foundry namespaces.7.5
  6. CVE-2025-64400Insufficient permission checks when pre-enrolling users Summary4.1
  7. CVE-2025-53709Access control issues impacting secure-upload service5.4
  8. CVE-2024-49589Foundry artifacts denial of service6.5
  9. CVE-2024-49581Access control issue impacting RV backed objects6.5
  10. CVE-2024-49588Multiple authenticated SQL injections in oracle-sidecar6.8
  11. CVE-2023-30968Stored XSS in gaia6.8
  12. CVE-2023-22836In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes the linter name from the default value, the renamed value may be visible to the rest of the stack’s tenants.3.5
  13. CVE-2023-30970Gotham table and Forward App Path traversal6.5
  14. CVE-2023-30954Gotham Video Broken Authentication2.7
  15. CVE-2023-30967Gotham Orbital Simulator path traversal9.8

The record

Peak rank
#95 in Feb 2023
Busiest month shown
Feb 2023, 7 CVEs
Months with a KEV entry
0 since Nov 2022
Monthly snapshots
5 since 2022
Palantir's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store