Where
-Infinity
0

Vendor Risk Score

See how linuxfoundation compares to other vendors in security performance

View Risk Score →

Software

linuxfoundation nats-server
33
linuxfoundation everest
29
linuxfoundation pytorch python
20
linuxfoundation yocto
20
linuxfoundation containerd
13
linuxfoundation runc
11
linuxfoundation onnx
10
linuxfoundation cups-filters
8
linuxfoundation tekton pipelines go
8
linuxfoundation automotive grade linux
6
linuxfoundation backstage
5
linuxfoundation edge virtualization engine
5
linuxfoundation spinnaker
5
linuxfoundation opendaylight
4
linuxfoundation argo continuous delivery kubernetes
3
linuxfoundation argo-cd
3
linuxfoundation ceph
3
linuxfoundation inspektor gadget
3
linuxfoundation kedro python
3
linuxfoundation opentelemetry instrumentation for java
3
linuxfoundation rekor
3
linuxfoundation antrea kubernetes
2
linuxfoundation cni network plugins
2
linuxfoundation dapr
2
linuxfoundation dojo node.js
2
linuxfoundation dojox node.js
2
linuxfoundation foomatic-filters
2
linuxfoundation fulcio
2
linuxfoundation podman desktop
2
linuxfoundation sigstore timestamp authority
2
linuxfoundation strimzi
2
linuxfoundation the update framework
2
linuxfoundation vitess
2
linuxfoundation backstage backend-common node.js
1
linuxfoundation backstage plugin-techdocs-node
1
linuxfoundation backstage\/backend defaults node.js
1
linuxfoundation backstage\/integration node.js
1
linuxfoundation backstage\/plugin-catalog-backend-module-unprocessed node.js
1
linuxfoundation backstage\/plugin-catalog-unprocessed-entities node.js
1
linuxfoundation backstage\/plugin-catalog-unprocessed-entities-common node.js
1
linuxfoundation backstage\/plugin-scaffolder-backend
1
linuxfoundation backstage\/plugin-scaffolder-backend node.js
1
linuxfoundation cloudnativepg kubernetes
1
linuxfoundation dex
1
linuxfoundation dragonfly go
1
linuxfoundation gardenctl
1
linuxfoundation harbor
1
linuxfoundation jaeger
1
linuxfoundation knative func
1
linuxfoundation kubewarden kubernetes
1

linuxfoundation SpinnakerSpinnaker: Improper yaml processing on kustomize bake operations

Risk 70
Severity
7.5
First published (updated )

linuxfoundation Nats-serverNATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled

Risk 43
Severity
7.5
First published (updated )

linuxfoundation Nats-serverNATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions

Risk 34
Severity
5.4
First published (updated )

linuxfoundation Nats-serverNATS Server: Remote crash via integer overflow in Connz pagination

Risk 44
Severity
7.7
First published (updated )

linuxfoundation Nats-serverNATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation Nats-serverNATS Server: MQTT retained and QoS replay bypass subscribe deny filters

Risk 22
Severity
4.3
First published (updated )

NATS NATS ServerNATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)

Risk 22
Severity
4.3
First published (updated )

linuxfoundation Nats-serverNATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check

Risk 40
Severity
5.3
First published (updated )

linuxfoundation Nats-serverNATS Server: MQTT SUBSCRIBE Protocol Injection via Leaf Node/Route Forwarding allows arbitrary NATS command injection

Risk 48
Severity
7.1
First published (updated )

linuxfoundation Nats-serverNATS Server: Pre-auth server crash via double INFO in leafnode handshake

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

linuxfoundation Nats-serverNATS Server: Subscribe Authz Bypass via Wildcard-Overlap

Risk 38
Severity
6.5
First published (updated )

linuxfoundation Nats-serverNATS Server: Route API Auth Bypass

Risk 65
Severity
8.8
First published (updated )

linuxfoundation Nats-serverNATS Server: Queue Subscribe Authz Bypass

Risk 38
Severity
6.5
First published (updated )

pip/onnxONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)

Risk 31
Severity
5.5
First published (updated )

OpenTelemetry OpenTelemetry Java InstrumentationOpenTelemetry Javaagent RMI context propagation allows resource exhaustion

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenTelemetry OpenTelemetry Java InstrumentationOpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

Risk 38
Severity
6.5
First published (updated )

maven/io.spinnaker.orca:orca-coreSpinnaker: Non-safe yaml deserialization allowing RCE when using specific types

Risk 79
Severity
8.8
First published (updated )

go/github.com/containerd/containerd/v2containerd: CRI checkpoint import allows local image tag poisoning

Risk 88
Severity
5.6
First published (updated )

linuxfoundation Containerdcontainerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

Risk 84
Severity
9.4
First published (updated )

go/github.com/containerd/containerd/v2containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

Risk 45
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/containerd/containerd/v2containerd CRI checkpoint restore CDI annotation smuggling

Risk 72
Severity
8.4
First published (updated )

linuxfoundation Containerdcontainerd image-triggered runtime DoS via unbounded group parsing

Risk 34
Severity
5.3
First published (updated )

linuxfoundation Runcrunc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

Risk 17
Severity
3.3
First published (updated )

pypi/kedroPath Traversal in kedro-org/kedro

Risk 52
Severity
7.1
First published (updated )

linuxfoundation Containerdcontainerd user ID handling bypass allows runAsNonRoot evasion

Risk 68
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Beproduct Beproduct\/nestjs-auth Node.jsTanStack Unspecified Vulnerability

Risk 95
Severity
9.6
First published (updated )

go/github.com/cloudnative-pg/cloudnative-pgCloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

Risk 82
Severity
9.4
First published (updated )

go/volcano.sh/volcanoVolcano: Webhook server vulnerable to OOM due to unbounded HTTP request body size

Risk 43
Severity
7.4
First published (updated )

linuxfoundation DaprDapr: Service Invocation path traversal ACL bypass

Risk 60
Severity
8.1
First published (updated )

npm/@backstage/plugin-catalog-backend-module-unprocessedBackstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203