Oscal-compass

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-57171

    Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)

    Last Modified: Aug 27, 2026
    Published: Aug 25, 2026

    CVE-2026-57170

    Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)

    Last Modified: Aug 28, 2026
    Published: Aug 25, 2026

    CVE-2026-52776

    Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

    Last Modified: Aug 26, 2026
    Published: Aug 25, 2026

    CVE-2026-54757

    Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

    Last Modified: Aug 26, 2026
    Published: Aug 25, 2026

    CVE-2026-46345

    compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

    Last Modified: Aug 17, 2026
    Published: Aug 17, 2026
    Items Per Page
    Oscal-Compass Vulnerabilities & Security CVEs | CVE-DB