Bifrost
This hub aggregates every CVE we track for Bifrost, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
2
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
3
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Bifrost.
- CVE-2026-90898Bifrost unauthenticated remote code execution via MCP stdio client registration9.8
- CVE-2026-86840Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion9.1
- CVE-2026-86242Unauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked Builds8.1
- CVE-2026-55245Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
- CVE-2022-39267Brokercap Bifrost vulnerable to authentication bypass for admin and monitor user groups8.8
- CVE-2022-39219Bifrost users using basic authntication can bypass write permission limit8.5
Product normalization is registry-driven with AI assist and human review. How it works