- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
As of 09/16/2026, Cloud Foundry recorded 2 security vulnerabilities in the last 90 days across 3 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, bosh-vsphere-cpi-release had the most security vulnerabilities in the Cloud Foundry ecosystem, with 1 vulnerabilities—approximately 50% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-41012BOSH vSphere CPI Improper Cert Validation | Exploitation statusNot known exploited | FixYes | Affected productbosh-vsphere-cpi-release | Published08/29/2026 | SeverityHigh |
CVE-2026-59335Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise | Exploitation statusNot known exploited | FixYes | Affected productUAA | Published08/25/2026 | SeverityHigh |
CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass | Exploitation statusNot known exploited | FixYes | Affected productUAA | Published06/11/2026 | SeverityCritical |
CVE-2026-22734Cloud Foundry UAA SAML 2.0 Signature Bypass | Exploitation statusNot known exploited | FixYes | Affected productUUA | Published04/16/2026 | SeverityHigh |
CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure | Exploitation statusNot known exploited | FixYes | Affected productUAA | Published05/13/2025 | SeverityLow |
CVE-2025-22216CVE-2025-22216 UAA Missing Zone Validation | Exploitation statusNot known exploited | FixYes | Affected productCloud Foundry UAA | Published01/31/2025 | SeverityMedium |
CVE-2024-38826CVE-2024-38826 Cloud Controller Denial of Service Attack | Exploitation statusNot known exploited | FixYes | Affected productCloud Foundry | Published11/11/2024 | SeverityMedium |
CVE-2024-37082 | Exploitation statusNot known exploited | FixYes | Affected producthaproxy-boshrelease | Published07/03/2024 | SeverityCritical |
CVE-2024-22279GoRouter Denial of Service Attack | Exploitation statusNot known exploited | FixYes | Affected productRouting Release | Published06/10/2024 | SeverityMedium |
CVE-2023-34061CVE-2023-34061 – Gorouter route pruning | Exploitation statusNot known exploited | FixYes | Affected productRouting Release | Published01/12/2024 | SeverityHigh |
CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter | Exploitation statusNot confirmed | FixYes | Affected productRouting | Published09/08/2023 | SeverityMedium |
CVE-2023-20885CF workflows leak credentials in system audit logs | Exploitation statusNot known exploited | FixNot confirmed | Affected productNotifications | Published06/16/2023 | SeverityMedium |
CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing | Exploitation statusNot confirmed | FixYes | Affected productCAPI | Published12/02/2020 | SeverityHigh |
CVE-2020-5422UAA password may appear in BOSH System Metrics Server process arguments | Exploitation statusNot confirmed | FixYes | Affected productBOSH System Metrics Server | Published10/02/2020 | SeverityUnknown |
CVE-2020-5420Gorouter is vulnerable to DoS attack via invalid HTTP responses | Exploitation statusNot confirmed | FixYes | Affected productRouting | Published09/03/2020 | SeverityHigh |
CVE-2020-5418Cloud Controller allows users with no roles to list droplets | Exploitation statusNot confirmed | FixYes | Affected productCAPI | Published09/03/2020 | SeverityLow |
CVE-2020-5417Cloud Controller may allow developers to claim sensitive routes | Exploitation statusNot confirmed | FixYes | Affected productCAPI | Published08/21/2020 | SeverityHigh |
CVE-2020-5416CF clusters with NGINX in front of them may be vulnerable to DoS | Exploitation statusNot confirmed | FixYes | Affected productRouting | Published08/21/2020 | SeverityHigh |
CVE-2020-5402UAA fails to check the state parameter when authenticating with external IDPs | Exploitation statusNot confirmed | FixYes | Affected productUAA | Published02/27/2020 | SeverityHigh |
CVE-2020-5401Cloud Foundry GoRouter is vulnerable to cache poisoning | Exploitation statusNot confirmed | FixYes | Affected productRouting | Published02/27/2020 | SeverityMedium |
CVE-2020-5400Cloud Controller logs environment variables from app manifests | Exploitation statusNot confirmed | FixYes | Affected productCAPI | Published02/27/2020 | SeverityHigh |
CVE-2020-5399CredHub does not properly enable TLS for MySQL database connections | Exploitation statusNot confirmed | FixYes | Affected productCredHub | Published02/12/2020 | SeverityHigh |
CVE-2019-11294CAPI leaks service broker URLs and GUIDs to space developers | Exploitation statusNot confirmed | FixNot confirmed | Affected productCAPI | Published12/19/2019 | SeverityMedium |
CVE-2019-11293UAA logs all query parameters with debug logging level | Exploitation statusNot confirmed | FixYes | Affected productUAA Release | Published12/06/2019 | SeverityHigh |
CVE-2019-11290Cloud Foundry UAA logs query parameters in tomcat access file | Exploitation statusNot confirmed | FixYes | Affected productUAA Release | Published11/25/2019 | SeverityHigh |
CVE-2019-11289A forged route service request using an invalid nonce can cause the gorouter to panic and crash | Exploitation statusNot confirmed | FixYes | Affected productRouting | Published11/19/2019 | SeverityHigh |
CVE-2019-11283Password leak in smbdriver logs | Exploitation statusNot confirmed | FixYes | Affected productSMB Volume | Published10/23/2019 | SeverityHigh |
CVE-2019-11282UAA is vulnerable to a Blind SCIM injection leading to information disclosure | Exploitation statusNot confirmed | FixYes | Affected productUAA Release | Published10/23/2019 | SeverityMedium |
CVE-2019-11279Privilege Escalation via Scope Manipulation in UAA | Exploitation statusNot confirmed | FixNot confirmed | Affected productUAA Release (OSS) | Published09/26/2019 | SeverityHigh |
CVE-2019-11278Privilege Escalation via Blind SCIM Injection in UAA | Exploitation statusNot confirmed | FixNot confirmed | Affected productUAA Release (OSS) | Published09/26/2019 | SeverityHigh |
CVE-2019-11277Volume Services is vulnerable to an LDAP injection attack | Exploitation statusNot confirmed | FixYes | Affected productCF NFS volume release | Published09/23/2019 | SeverityHigh |
CVE-2019-11274UAA SCIM Filter XSS | Exploitation statusNot confirmed | FixNot confirmed | Affected productUAA Release (OSS) | Published08/09/2019 | SeverityMedium |
CVE-2019-3800CF CLI writes the client id and secret to config file | Exploitation statusNot confirmed | FixNot confirmed | Affected productCF CLI Release | Published08/05/2019 | SeverityMedium |
CVE-2019-11270UAA clients.write vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Affected productUAA Release (OSS) | Published08/05/2019 | SeverityHigh |
CVE-2019-3794UAA - Login app subject to clickjacking attack | Exploitation statusNot confirmed | FixYes | Affected productUAA Release (OSS) | Published07/18/2019 | SeverityMedium |
CVE-2019-11268UAA SQL Identity Zone Vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Affected productUAA Release (OSS) | Published07/11/2019 | SeverityMedium |
CVE-2019-3787UAA defaults email address to an insecure domain | Exploitation statusNot confirmed | FixYes | Affected productUAA Release (OSS) | Published06/19/2019 | SeverityHigh |
CVE-2019-11271Bosh Deployment logs leak sensitive information | Exploitation statusNot confirmed | FixYes | Affected productBOSH | Published06/18/2019 | SeverityMedium |
CVE-2019-3801Java Projects using HTTP to fetch dependencies | Exploitation statusNot confirmed | FixYes | Affected productCredHub | Published04/25/2019 | SeverityHigh |
CVE-2019-3788UAA redirect-uri allows wildcard in the subdomain | Exploitation statusNot confirmed | FixYes | Affected productUAA Release (OSS) | Published04/25/2019 | SeverityHigh |
CVE-2019-3789Gorouter allows space developer to hijack route services hosted outside the platform | Exploitation statusNot confirmed | FixYes | Affected productCF Routing | Published04/24/2019 | SeverityHigh |
CVE-2019-3786BBR could run arbitrary scripts on deployment VMs | Exploitation statusNot confirmed | FixYes | Affected productBOSH Backup and Restore | Published04/24/2019 | SeverityHigh |
CVE-2019-3798Escalation of Privileges in Cloud Controller | Exploitation statusNot confirmed | FixYes | Affected productCAPI-release | Published04/17/2019 | SeverityMedium |
CVE-2019-3785Cloud Controller provides signed URL with write authorization to read only user | Exploitation statusNot confirmed | FixYes | Affected productCAPI | Published03/13/2019 | SeverityMedium |
CVE-2019-3779Cloud Foundry Container Runtime allows a user to bypass security policy when talking to ETCD | Exploitation statusNot confirmed | FixYes | Affected productCloud Foundry Container Runtime (CFCR) | Published03/08/2019 | SeverityHigh |
CVE-2019-3780Cloud Foundry Container Runtime Leaks IAAS Credentials | Exploitation statusNot confirmed | FixYes | Affected productCloud Foundry Container Runtime (CFCR) | Published03/08/2019 | SeverityCritical |
CVE-2019-3784Cloud Foundry Stratos contains a Session Collision Vulnerability | Exploitation statusNot confirmed | FixYes | Affected productStratos | Published03/07/2019 | SeverityHigh |
CVE-2019-3781CF CLI does not sanitize user's password in verbose/trace/debug | Exploitation statusNot confirmed | FixYes | Affected productCF CLI | Published03/07/2019 | SeverityHigh |
CVE-2019-3783Cloud Foundry Stratos Deploys With Public Default Session Store Secret | Exploitation statusNot confirmed | FixYes | Affected productStratos | Published03/07/2019 | SeverityHigh |
CVE-2019-3775UAA allows users to modify their own email address | Exploitation statusNot confirmed | FixYes | Affected productUAA Release (OSS) | Published03/07/2019 | SeverityHigh |
CVE-2019-3782CredHub CLI writes environment variable credentials to disk | Exploitation statusNot confirmed | FixYes | Affected productCredHub CLI | Published02/13/2019 | SeverityMedium |
CVE-2018-15754UAA can issue tokens across identity providers if users with matching usernames exist | Exploitation statusNot confirmed | FixYes | Affected productUAA Release | Published12/13/2018 | SeverityMedium |
CVE-2018-15800Timing attack allows extraction of signing key in Bits Service | Exploitation statusNot confirmed | FixYes | Affected productBits Service Release | Published12/10/2018 | SeverityHigh |
CVE-2018-15797NFS Volume release errand leaks cf admin credentials in logs | Exploitation statusNot confirmed | FixYes | Affected productNFS Volume Release | Published12/05/2018 | SeverityHigh |
CVE-2018-15761UAA Privilege Escalation | Exploitation statusNot confirmed | FixYes | Affected productUAA | Published11/19/2018 | SeverityCritical |
CVE-2018-15796Signing Key Extraction in Bits Service Release | Exploitation statusNot confirmed | FixYes | Affected productbits-service-release | Published11/09/2018 | SeverityHigh |
CVE-2018-15755CF networking internal policy server SQL injection | Exploitation statusNot confirmed | FixYes | Affected productCF Networking Release | Published10/12/2018 | SeverityMedium |
CVE-2018-11082Cloud Foundry UAA MFA does not prevent brute force of MFA code | Exploitation statusNot confirmed | FixYes | Affected productUAA Release | Published10/05/2018 | SeverityMedium |
CVE-2018-11083Bosh accepts refresh tokens in place of an access token | Exploitation statusNot confirmed | FixYes | Affected productBOSH | Published10/05/2018 | SeverityHigh |
CVE-2018-1264Log Cache logs UAA client secret on startup | Exploitation statusNot confirmed | FixYes | Affected productlog-cache-release | Published10/05/2018 | SeverityCritical |
CVE-2018-11084Garden-runC prevents deletion of some app environments | Exploitation statusNot confirmed | FixYes | Affected productGarden-runC | Published09/18/2018 | SeverityMedium |
CVE-2018-1223 | Exploitation statusNot confirmed | FixYes | Affected productContainer Runtime | Published09/17/2018 | SeverityUnknown |
CVE-2018-11047 | Exploitation statusNot confirmed | FixYes | Affected productCloud Foundry UAA | Published07/24/2018 | SeverityUnknown |
CVE-2016-0708 | Exploitation statusNot confirmed | FixNot confirmed | Affected productCloud Foundry | Published07/11/2018 | SeverityUnknown |
CVE-2018-11041 | Exploitation statusNot confirmed | FixNot confirmed | Affected productCloud Foundry UAA | Published06/25/2018 | SeverityUnknown |
CVE-2018-1265 | Exploitation statusNot confirmed | FixYes | Affected productDiego | Published06/06/2018 | SeverityUnknown |
CVE-2018-1269 | Exploitation statusNot confirmed | FixYes | Affected productLoggregator | Published06/06/2018 | SeverityUnknown |
CVE-2018-1268 | Exploitation statusNot confirmed | FixYes | Affected productLoggregator | Published06/06/2018 | SeverityUnknown |
CVE-2018-1193 | Exploitation statusNot confirmed | FixNot confirmed | Affected productCloud Foundry Router | Published05/23/2018 | SeverityUnknown |
CVE-2018-1276 | Exploitation statusNot confirmed | FixNot confirmed | Affected productWindows2012R2 stemcell | Published05/17/2018 | SeverityUnknown |
CVE-2018-1262 | Exploitation statusNot confirmed | FixNot confirmed | Affected productCloudFoundry UAA | Published05/15/2018 | SeverityUnknown |
CVE-2018-1277 | Exploitation statusNot confirmed | FixNot confirmed | Affected productGarden-runC | Published04/30/2018 | SeverityUnknown |
CVE-2016-2169 | Exploitation statusNot confirmed | FixNot confirmed | Affected productCloud Controller | Published04/18/2018 | SeverityUnknown |
CVE-2018-1191 | Exploitation statusNot confirmed | FixNot confirmed | Affected productGarden-runC | Published03/29/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan