woodpecker-ci
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 3
en
Verify to analyze this security profile
As of 09/18/2026, woodpecker-ci recorded 3 security vulnerabilities in the last 90 days across 1 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, woodpecker had the most security vulnerabilities in the woodpecker-ci ecosystem, with 3 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-61549Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend | Exploitation statusNot known exploited | FixYes | Affected productwoodpecker | Published09/15/2026 | SeverityCritical |
CVE-2026-58370Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author Name | Exploitation statusNot known exploited | FixYes | Affected productwoodpecker | Published06/30/2026 | SeverityCritical |
CVE-2026-58369Woodpecker < 3.15.0 - Unauthenticated NULL Pointer Dereference in /api/orgs/lookup Enables Log-Flooding Denial of Service | Exploitation statusNot known exploited | FixYes | Affected productwoodpecker | Published06/30/2026 | SeverityMedium |
CVE-2026-50141Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation | Exploitation statusNot known exploited | FixNot confirmed | Affected productwoodpecker | Published06/18/2026 | SeverityHigh |
CVE-2024-41122Custom environment variables allow to alter execution flow of plugins in Woodpecker | Exploitation statusNot known exploited | FixNot confirmed | Affected productwoodpecker | Published07/19/2024 | SeverityHigh |
CVE-2024-41121Custom workspace allow to overwrite plugin entrypoint executable in Woodpecker | Exploitation statusNot known exploited | FixNot confirmed | Affected productwoodpecker | Published07/19/2024 | SeverityHigh |
CVE-2023-40034Repositoty takeover in woodpecker-ci | Exploitation statusNot known exploited | FixNot confirmed | Affected productwoodpecker | Published08/16/2023 | SeverityHigh |
CVE-2022-29947 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published04/29/2022 | SeverityUnknown |