linuxfoundation

523 tracked vulnerabilities.

CVE-2026-25153 HIGH
@backstage/plugin-techdocs-node < 1.13.11 and 1.14.0 - Remote Code Execution via MkDocs Hooks Configuration
Jan 30, 2026
CVSS 7.7
EPSS 0.00
CVE-2026-25152 MEDIUM
@backstage/plugin-techdocs-node < 1.14.1 and 1.13.11 - Path Traversal via Symlink Processing in Local Generator
Jan 30, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-24905 HIGH
inspektor-gadget < 0.48.1 and < 0.51.1 - Command Injection via Unsafe Makefile Parameter Embedding
Jan 29, 2026
CVSS 7.8
EPSS 0.00
CVE-2026-24835 HIGH
Podman Desktop <1.25.1 - Auth Bypass
Jan 28, 2026
CVSS 7.1
EPSS 0.00
CVE-2026-24747 HIGH
PyTorch < 2.10.0 - Remote Code Execution via Malicious Checkpoint File
Jan 27, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-24408 NONE
sigstore-python < 4.2.0 - Cross-Site Request Forgery in OAuth Authentication Flow
Jan 26, 2026
EPSS 0.00
CVE-2026-24003 MEDIUM
EVerest <= 2025.12.1 - Incorrect Authorization via ISO 15118-2 MQTT Messages
Jan 26, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-24124 CRITICAL
Dragonfly <2.4.1-rc.0 - Info Disclosure
Jan 22, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-24117 MEDIUM
Rekor < 1.5.0 - Server-Side Request Forgery via Public Key Retrieval Endpoint
Jan 22, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-23831 MEDIUM
Rekor <1.4.3 - Nil Pointer Dereference
Jan 22, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-24048 LOW
Backstage backend-defaults < 0.12.2 - Server-Side Request Forgery via FetchUrlReader Redirect Handling
Jan 21, 2026
CVSS 3.5
EPSS 0.00
CVE-2026-23955 MEDIUM
EVerest <2025.9.0 - Memory Corruption
Jan 21, 2026
CVSS 4.2
EPSS 0.00
CVE-2026-22772 MEDIUM
Fulcio < 1.8.5 - Server-Side Request Forgery via MetaIssuer URL Validation Bypass
Jan 12, 2026
CVSS 5.8
EPSS 0.00
CVE-2025-61611 HIGH
Modem - Denial of Service
Mar 09, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-68141 HIGH
EVerest < 2025.10.0 - Denial of Service via DC_ChargeLoopRes Message Deserialization
Jan 21, 2026
CVSS 7.4
EPSS 0.00
CVE-2025-68140 MEDIUM
EVerest < 2025.9.0 - Unauthenticated Incorrect Authorization via Session ID 0
Jan 21, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-68139 MEDIUM
EVerest <2025.12.1 - Info Disclosure
Jan 21, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-68138 MEDIUM
libocpp < 0.30.1 - Memory Leak via Unfreed strdup Pointers
Jan 21, 2026
CVSS 4.7
EPSS 0.00
CVE-2025-68137 HIGH
EVerest < 2025.10.0 - Infinite Loop via SdpPacket Header Parsing
Jan 21, 2026
CVSS 8.3
EPSS 0.00
CVE-2025-68136 HIGH
EVerest < 2025.10.0 - Denial of Service via ISO15118-20 SDP Request Handling
Jan 21, 2026
CVSS 7.4
EPSS 0.00
CVE-2025-68135 MEDIUM
EVerest < 2025.10.0 - Denial of Service via TbdController Exception Handling
Jan 21, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-68134 HIGH
EVerest < 2025.10.0 - Denial of Service via Assert Function Error Handling
Jan 21, 2026
CVSS 7.4
EPSS 0.00
CVE-2025-68132 MEDIUM
EVerest < 2025.12.0 - Out-of-bounds Read in DZG_GSH01 SLIP Parser
Jan 21, 2026
CVSS 4.6
EPSS 0.00
CVE-2025-68133 HIGH
EVerest < 2025.10.0 - Denial of Service via Unlimited TCP Connection Exhaustion
Jan 21, 2026
CVSS 7.4
EPSS 0.00
CVE-2025-61916 HIGH
Spinnaker < 2025.1.6, 2025.2.3, 2025.3.0 - Server-Side Request Forgery via Artifact Provider URL Input
Jan 05, 2026
CVSS 7.9
EPSS 0.00