CVE Tools

Puppet Server

8 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Puppet Server, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Puppet Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Puppet Server CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical225%
  • High225%
  • Medium338%
  • Low113%

Latest CVEs

The 8 most recently published vulnerabilities affecting Puppet Server.

  1. CVE-2023-5255Denial of Service for Revocation of Auto Renewed Certificates4.4
  2. CVE-2023-1894A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed do...5.3
  3. CVE-2021-27023A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-10000079.8
  4. CVE-2020-7943Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource ...7.5
  5. CVE-2018-11751Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0.5.4
  6. CVE-2017-2295Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization...8.2
  7. CVE-2016-2785Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leverag...9.8
  8. CVE-2014-7170Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.1.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store