Vulnerabilities in project-zot
5 resultsVexday analysis
Project-Zot apresenta footprint reduzido com 4 CVEs catalogadas, nenhuma em exploração ativa e sem críticas registradas. A ausência de divulgações recentes indica estabilidade relativa, porém a fraqueza dominante em controle de privilégios (CWE-269) permanece como vetor de risco potencial que merece monitoramento.
CVE-2026-61833HIGHzot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletionEPSS 0.4%CVE-2025-23208HIGHIdP group membership revocation ignored in zotEPSS 0.4%CVE-2024-39897MEDIUMCache driver GetBlob() allows read access to any blob without access control checkEPSS 0.3%CVE-2026-31801HIGHzot create-only policy allows overwrite attempts of existing latest tag (update permission not required)EPSS 0.2%CVE-2025-48374MEDIUMzot logs secretsEPSS 0.2%