Where
-Infinity
0

maven/org.apache.pulsar:pulsar-brokerApache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints

Risk 29
Severity
6.4
EPSS
0.04%
First published (updated )

CVE-2024-29834: Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints

First published (updated )

maven/org.apache.pulsar:pulsar-brokerApache Pulsar: Improper Authorization For Topic-Level Policy Management

Risk 29
Severity
6.4
EPSS
0.04%
First published (updated )

maven/org.apache.pulsar:pulsar-functions-workerApache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying

Risk 58
Severity
8.8
EPSS
0.04%
First published (updated )

CVE-2024-27317: Apache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.apache.pulsar:pulsar-functions-workerApache Pulsar: Pulsar Functions Worker's Archive Extraction Vulnerability Allows Unauthorized File Modification

Risk 61
Severity
10
EPSS
0.04%
First published (updated )

maven/org.apache.pulsar:pulsar-functions-workerApache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution

Risk 61
Severity
9.9
EPSS
0.04%
First published (updated )

CVE-2024-27135: Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution

CVE-2022-34321: Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint

maven/org.apache.pulsar:pulsar-proxyApache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint

Risk 57
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache PulsarApache Pulsar: Timing attack in SASL token signature verification

Risk 60
Severity
7.4
First published (updated )

maven/org.apache.pulsar:pulsar-websocketApache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoS

Risk 46
Severity
7.5
First published (updated )

Apache PulsarApache Pulsar Function Worker: Incorrect Authorization for Function Worker Can Leak Sink/Source Credentials

Risk 61
Severity
8.2
First published (updated )

Apache PulsarApache Pulsar: Broker does not always disconnect client when authentication data expires

Risk 39
Severity
6.5
First published (updated )

Apache PulsarApache Pulsar: Incorrect Authorization for Function Worker when using mTLS Authentication through Pulsar Proxy

Risk 70
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache PulsarApache Pulsar Broker: Incorrect Authorization Validation for Rest Producer

Risk 61
Severity
8.2
First published (updated )

Apache PulsarApache Pulsar C++/Python OAuth Clients prior to 3.0.0 were vulnerable to an MITM attack due to Disabled Certificate Validation

Risk 75
Severity
8.1
First published (updated )

Apache PulsarDisabled Certificate Validation makes Broker, Proxy Admin Clients vulnerable to MITM attack

Risk 35
Severity
5.9
First published (updated )

Apache PulsarDisabled Hostname Verification makes Brokers, Proxies vulnerable to MITM attack

Risk 35
Severity
5.9
First published (updated )

Apache PulsarApache Pulsar Proxy target broker address isn't validated

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache PulsarImproper Hostname Verification in Java Client and Proxy can expose authentication data via MITM

Risk 36
Severity
5.9
First published (updated )

maven/org.apache.pulsar:pulsarPulsar Admin API allows access to data from other tenants using getMessageById API

Risk 39
Severity
6.5
First published (updated )

Apache PulsarAuthentication with JWT allows use of “none”-algorithm

Risk 86
Severity
9.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203