linuxfoundation
21 known vulnerabilities affecting linuxfoundation products.
Products
nats-server 7
spinnaker 2
tekton_pipelines 2
torchvision 1
cert-manager 1
harbor 1
kedro 1
onnx 1
opentelemetry_instrumentation_for_java 1
oras 1
podman_desktop 1
runc 1
sigstore_timestamp_authority 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-21626 | Medium | 18.1% | 8.6 | runc is a CLI tool for spawning and running containers on Linux according to the… | |
| CVE-2026-55175 | Medium | 1.1% | 7.5 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to … | |
| CVE-2026-44795 | Medium | 1.0% | 8.8 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to … | |
| CVE-2026-33701 | Medium | 0.9% | 9.8 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation a… | |
| CVE-2026-40938 | Medium | 0.8% | 7.5 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style … | |
| CVE-2026-35171 | Medium | 0.7% | 9.8 | Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allo… | |
| CVE-2026-29785 | Medium | 0.7% | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-33218 | Medium | 0.6% | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-27889 | Medium | 0.6% | 7.5 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-33211 | Medium | 0.6% | 9.6 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style … | |
| CVE-2026-4404 | Medium | 0.5% | 9.4 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allow… | |
| CVE-2026-34045 | Medium | 0.5% | 8.2 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. … | |
| CVE-2026-33247 | Medium | 0.4% | 7.4 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-50151 | Medium | 0.4% | 7.5 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/rem… | |
| CVE-2026-33216 | Medium | 0.4% | 8.6 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-65918 | Medium | 0.3% | 7.1 | PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-… | |
| CVE-2026-33217 | Medium | 0.3% | 7.1 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-49114 | Medium | 0.2% | 7.1 | In ONNX before 1.21.0, the 'save_external_data' function builds the external-dat… | |
| CVE-2026-62290 | Medium | 0.1% | 7.3 | cert-manager adds certificates and certificate issuers as resource types in Kube… | |
| CVE-2026-33219 | Low | 0.5% | 5.3 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native me… | |
| CVE-2026-49835 | Low | 0.4% | 5.9 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior… |