Cf deployment
This hub aggregates every CVE we track for Cf deployment, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
2
Critical
8
High
0
In CISA KEV
Severity distribution
HIGH8MEDIUM5CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
1
0
4
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Cf deployment.
- CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass9.0
- CVE-2026-40965Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed t...10.0
- CVE-2026-40964Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and ...7.5
- CVE-2026-41013Tenant-controlled comma smuggles arbitrary CIFS mount options8.1
- CVE-2026-22726Route Services Firewall Bypass5.0
- CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
- CVE-2023-34061CVE-2023-34061 – Gorouter route pruning7.5
- CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter5.3
- CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing7.5
- CVE-2020-5420Gorouter is vulnerable to DoS attack via invalid HTTP responses7.7
- CVE-2020-5418Cloud Controller allows users with no roles to list droplets4.3
- CVE-2020-5417Cloud Controller may allow developers to claim sensitive routes8.8
- CVE-2020-5416CF clusters with NGINX in front of them may be vulnerable to DoS6.5
- CVE-2019-11283Password leak in smbdriver logs8.8
- CVE-2019-11282UAA is vulnerable to a Blind SCIM injection leading to information disclosure4.3
Product normalization is registry-driven with AI assist and human review. How it works