octopus
DevTools & CIcommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting octopus.
- CVE-2026-3237In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint tha...4.3
- CVE-2026-0704In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways ...9.1
- CVE-2025-0539In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to...8.8
- CVE-2025-0588In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user...4.9
- CVE-2025-0513In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the...5.4
- CVE-2025-0526In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways ...5.4
- CVE-2025-0525In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in fur...7.5
- CVE-2025-0589In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which w...5.3
- CVE-2024-9194SQL Injection in the Octopus Server REST API9.8
- CVE-2024-1656Affected versions of Octopus Server had a weak content security policy.2.6
- CVE-2024-7998In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.2.6
- CVE-2024-6972In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.6.5
- CVE-2024-4811In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.2.2
- CVE-2024-4456In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.4.1
- CVE-2024-4226It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of...3.5