cloudfoundry
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting cloudfoundry.
- CVE-2026-47829Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director7.8
- CVE-2026-47828Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution via Man-in-the-Middle Credential Replay8.8
- CVE-2026-47826blobs.yaml Path Traversal Allows File Writes9.1
- CVE-2026-41857BOSH CLI Shell Injection7.8
- CVE-2026-22726Route Services Firewall Bypass5.0
- CVE-2026-22727Cloud Foundry unprotected internal endpoints7.5
- CVE-2026-22723UAA User Token Revocation logic error6.5
- CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
- CVE-2024-22279GoRouter Denial of Service Attack5.9
- CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter5.3
- CVE-2023-20882In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right ci...5.9
- CVE-2023-20881Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate u...8.1
- CVE-2023-20903This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to ...4.3
- CVE-2022-31733Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without...9.1
- CVE-2018-25046Path traversal in code.cloudfoundry.org/archiver9.1