Solution sectors / devtools-ci
Developer Tools & CI/CD
Developer tooling — IDEs, CI/CD pipelines, source control and artifact registries — has deep access to source code and build infrastructure, making it a high-value supply-chain target. This hub tracks CVEs across it.
Cumulative CVEs
8,379
across 251 monthly snapshots
Latest month
236 · proj
-33.1% MoM · +210.5% YoY
Peak month
353
Aug 26
KEV this month
1
26 vendors affected
CVEs per month
Newest period on the right. Click a point to open that monthly report.
Deployment mix
How this sector's software is typically delivered (month in progress) — whether you patch it yourself or a vendor does. AI-assisted vendor classification.
- On-prem54%
- Mixed42%
- SaaS4%
Latest CVEs in this sector
The 15 most recently published vulnerabilities tagged to Developer Tools & CI/CD.
- CVE-2026-55847Allure: Stored XSS via unescaped ANSI helper in Allure report status message/trace rendering6.1
- CVE-2026-55846Allure: Path Traversal in Allure Report HTTP Server Allows Arbitrary File Read6.2
- CVE-2025-24890gix-sec safe.directory protections absent for elevated administrators6.8
- CVE-2026-90682Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow5.3
- CVE-2026-90681Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds3.3
- CVE-2026-90780SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content7.5
- CVE-2026-90779SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter7.5
- CVE-2026-90778SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag7.5
- CVE-2026-90769Open Notebook before 1.11.0 Server-Side Request Forgery via link-source7.7
- CVE-2026-90679Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does n...4.3
- CVE-2026-85706Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabKEV10.0
- CVE-2026-87719Deserialization of Untrusted Data in GitLab9.9
- CVE-2026-50018Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions6.5
- CVE-2026-50013Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode7.5
- CVE-2026-54174melange: Incomplete package integrity verification allows data section substitution8.3
Weakness fingerprint
Top CWE classes in this sector, latest monthly snapshot (month in progress).
Subsectors
Breakdown for the latest monthly snapshot (month in progress).
| Subsector | CVEs | Crit | KEV | Vendors | MoM | Top products |
|---|---|---|---|---|---|---|
| ci-cd | 52 | 6 | 1 | 10 | — | jenkins (19) · rancher (5) · red hat ansible automation platform 2 (3) |
| ide-editor | 38 | 1 | · | 3 | — | youtrack (22) · microsoft visual studio 2022 version 17.14 (7) · intellij idea (5) |
| build-test-tools | 14 | · | · | 7 | — | nexus repository 3 (5) · sipp (3) · hoverfly (2) |
| source-control | 8 | 2 | · | 3 | — | forgejo (3) · gitpython (3) · akana (2) |
| — | 5 | · | · | 2 | — | enterprise server (3) · systemlink server (2) |
| artifact-registry | 1 | · | · | 1 | — | composer (1) |
Sector classification is AI-assisted with human review. How tagging works · Report a misclassification