Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CGA-56gr-74mm-c3qp
    No fix available
    Packages

    airflow-core-2

    Summary

    Published
    9 Sept 2026
    CGA-594x-435p-96fc
    Fix available
    Packages

    neuvector-enforcer-fips

    Summary

    Published
    9 Sept 2026
    CGA-g36f-5729-vvff
    Fix available
    Packages

    filebeat-fips-9.5

    Summary

    Published
    9 Sept 2026
    CGA-2j8c-vh3c-6vf7
    Fix available
    Packages

    gcp-compute-persistent-disk-csi-driver-1.16

    Summary

    Published
    9 Sept 2026
    CGA-rpfq-c2w6-rf89
    No fix available
    Packages

    airflow-core-2

    Summary

    Published
    9 Sept 2026
    CGA-4xf9-fpfp-7ccv
    Fix available
    Packages

    gcp-compute-persistent-disk-csi-driver-1.16

    Summary

    Published
    9 Sept 2026
    CGA-hpjm-xw8h-9r55
    No fix available
    Packages

    airflow-core-2

    Summary

    Published
    9 Sept 2026
    CGA-gq3r-2hjv-2mm5
    No fix available
    Packages

    airflow-core-2

    Summary

    Published
    9 Sept 2026
    CGA-3q3x-gr62-r35j
    No fix available
    Packages

    loki-3.5-promtail

    Summary

    Published
    9 Sept 2026
    CGA-mgvv-6c89-5m5j
    No fix available
    Packages

    loki-3.5-promtail

    Summary

    Published
    9 Sept 2026
    CGA-vvrq-7p8v-v467
    Fix available
    Packages

    crossplane-provider-azure-storagecache

    Summary

    Published
    9 Sept 2026
    CGA-hxv5-376g-mqmw
    Fix available
    Packages

    cloud-provider-azure-cloud-controller-manager-fips-1.35

    Summary

    Published
    9 Sept 2026
    CGA-2vjq-xc8m-rwjx
    Fix available
    Packages

    percona-backup-mongodb-2.14

    Summary

    Published
    9 Sept 2026
    CGA-42w5-4vpr-h223
    Fix available
    Packages

    percona-backup-mongodb-2.14

    Summary

    Published
    9 Sept 2026
    CGA-q99j-55mq-g46q
    Fix available
    Packages

    calico-whisker-backend-3.32, calico-whisker-backend-3.32

    Summary

    Published
    9 Sept 2026
    CGA-h628-w92g-qcrw
    Fix available
    Packages

    crossplane-provider-aws-sns, crossplane-provider-aws-sns

    Summary

    Published
    9 Sept 2026
    CGA-xg84-35mj-f9fx
    Fix available
    Packages

    percona-backup-mongodb-2.14

    Summary

    Published
    9 Sept 2026
    CGA-9chj-37p5-jw4g
    No fix available
    Packages

    knative-serving-fips-1.20-controller

    Summary

    Published
    9 Sept 2026
    CGA-mqrw-94rr-wh47
    Fix available
    Packages

    tekton-pipelines-entrypoint-fips-1.11

    Summary

    Published
    9 Sept 2026
    CGA-7p62-w4w9-wjmc
    Fix available
    Packages

    blob-csi-fips-1.23

    Summary

    Published
    9 Sept 2026
    CGA-f96w-q928-4mgq
    Fix available
    Packages

    blob-csi-fips-1.23

    Summary

    Published
    9 Sept 2026
    CGA-x24c-mpm7-h6qw
    Fix available
    Packages

    gatekeeper-3.21, gatekeeper-3.21

    Summary

    Published
    9 Sept 2026
    CGA-gqq3-29r5-mf4w
    Fix available
    Packages

    kubeflow-pipelines-persistence_agent, kubeflow-pipelines-persistence_agent

    Summary

    Published
    9 Sept 2026
    CVE-2026-86775
    Fix available
    Packages

    Summary

    knowns before 0.30.0 Path Traversal via Document API

    Published
    9 Sept 2026
    CVE-2026-86774
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy

    Published
    9 Sept 2026
    CVE-2026-86773
    Fix available
    Packages

    Summary

    Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints

    Published
    9 Sept 2026
    CGA-7x2q-r659-8c47
    Fix available
    Packages

    terraform-provider-azuread, terraform-provider-azuread

    Summary

    Published
    9 Sept 2026
    CGA-hrf4-59w6-xvqh
    Fix available
    Packages

    py3.10-accelerate-cuda-13.0

    Summary

    Published
    9 Sept 2026
    CVE-2026-86772
    Fix available
    Packages

    Summary

    Snipe-IT 8.6.3 Stored XSS via Department Names

    Published
    9 Sept 2026
    CGA-3fj6-g6v3-8vv3
    Fix available
    Packages

    tofu-controller, tofu-controller

    Summary

    Published
    9 Sept 2026
    CVE-2026-86771
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num

    Published
    9 Sept 2026
    CVE-2026-86770
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation

    Published
    9 Sept 2026
    CVE-2026-86769
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout

    Published
    9 Sept 2026
    CVE-2026-86768
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Improper Input Validation via API Checkout

    Published
    9 Sept 2026
    CVE-2026-86767
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Cross-Company Read via requested-assets

    Published
    9 Sept 2026
    CGA-9cq7-4c7m-95rw
    Fix available
    Packages

    kubernetes-csi-external-resizer-fips

    Summary

    Published
    9 Sept 2026
    CVE-2026-86766
    Fix available
    Packages

    Summary

    Snipe-IT 8.6.3 Race Condition via Consumable Checkout

    Published
    9 Sept 2026
    CGA-qp4q-j3jg-mc3f
    No fix available
    Packages

    kubernetes-fips-1.36

    Summary

    Published
    9 Sept 2026
    CVE-2026-86765
    Fix available
    Packages

    Summary

    Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint

    Published
    9 Sept 2026
    CVE-2026-86764
    Fix available
    Packages

    Summary

    Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components

    Published
    9 Sept 2026
    CGA-p3pw-v9rg-r7qg
    Fix available
    Packages

    cloud-provider-aws-1.35-cloud-controller-manager, cloud-provider-aws-1.35-cloud-controller-manager

    Summary

    Published
    9 Sept 2026
    CGA-wh56-v288-4fh5
    No fix available
    Packages

    kubernetes-fips-1.36

    Summary

    Published
    9 Sept 2026
    CVE-2026-86763
    No fix available
    Packages

    Summary

    snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer

    Published
    9 Sept 2026
    CGA-8f2r-j2h7-vpp4
    No fix available
    Packages

    kubernetes-fips-1.36

    Summary

    Published
    9 Sept 2026
    CGA-cgfw-p5m5-wvm8
    No fix available
    Packages

    kubernetes-fips-1.36

    Summary

    Published
    9 Sept 2026
    CVE-2026-86762
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Authentication Bypass via API Middleware

    Published
    9 Sept 2026
    CVE-2026-86761
    Fix available
    Packages

    Summary

    snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints

    Published
    9 Sept 2026
    CGA-9336-45hq-6h94
    No fix available
    Packages

    kubernetes-fips-1.36

    Summary

    Published
    9 Sept 2026
    CVE-2026-86760
    Fix available
    Packages

    Summary

    snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag

    Published
    9 Sept 2026
    CGA-g87w-v3qr-r4fg
    No fix available
    Packages

    kubernetes-fips-1.36

    Summary

    Published
    9 Sept 2026