tukaani
Security Risk Profile
28
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 20, 2015 to present
9
Total CVEs
3
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
5.8
Base severity
Avg EPSS
10%
Exploit probability
Unpatched
0
Critical/High
Risk Level
28/100
low
Severity Distribution
Critical
1High
2Medium
1Low
2Exploit Likelihood
>50% chance
020-50%
05-20%
1<5%
0Age Distribution
Common Weaknesses (CWE)
1
Input Validation
2
2
Buffer Overflow
1
Most Affected Products
1. redhat/xz8
2. Tukaani XZ7
3. redhat/gzip7
4. debian/xz-utils3
5. Tukaani XZ Utils3
Recent Vulnerabilities
See more →CVE-2026-34743
CVSS 1.7low
XZ Utils: Buffer overflow in lzma_index_append()
4/2/2026
https://seclists.org/oss-sec/2026/q1/428
unknown
Fwd: XZ Utils 5.8.3 and a security fix
3/31/2026🔧 No Patch
https://seclists.org/oss-sec/2025/q2/9
unknown
XZ Utils: Thaded decoder fes memory too early (CVE-2025-31115)
4/3/2025🔧 No Patch
https://seclists.org/oss-sec/2024/q3/78
unknown
Landlock news #4
7/16/2024🔧 No Patch
CVE-2024-3094
CVSS 10.0EPSS 10%critical
Xz: malicious code in distributed source
3/29/2024
REDHAT-BUG-2234987
CVSS 1.0low
8/25/2023🔧 No Patch
CVE-2020-22916
CVSS 5.5medium
8/22/2023🔧 No Patch
CVE-2022-1271
CVSS 8.8high
Tukaani XZ Utils xzgrep Argument Injection Remote Code Execution Vulnerability
4/7/2022
CVE-2015-4035
CVSS 7.8high
5/20/2015
Monitor tukaani in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.