Vulnerabilities in stacklok
12 resultsVexday analysis
Stacklok apresenta 9 vulnerabilidades catalogadas, nenhuma em exploração ativa atualmente e sem críticas críticas registradas. A fraqueza dominante é CWE-400 (Consumo não controlado de recursos), sugerindo problemas de resiliência; como nenhuma foi publicada nos últimos 90 dias, o risco é estável e de baixa prioridade operacional.
CVE-2024-31455MEDIUMMinder GetRepositoryByName data leakEPSS 0.8%CVE-2024-27916HIGH`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated userEPSS 0.7%CVE-2024-34084HIGHMinder's Github Webhook Handler vulnerable to denial of service from un-validated requestsEPSS 0.6%CVE-2024-27093MEDIUMMinder trusts client-provided mapping from repo name to upstream IDEPSS 0.6%CVE-2024-35238MEDIUMDenial of service of Minder Server from maliciously crafted GitHub attestationsEPSS 0.5%CVE-2024-35185MEDIUMDenial of service of Minder Server with attacker-controlled REST endpointEPSS 0.5%CVE-2024-37904MEDIUMDenial of service from maliciously configured Git repository in MinderEPSS 0.5%CVE-2024-35194MEDIUMStacklok Minder vulnerable to denial of service from maliciously crafted templatesEPSS 0.4%CVE-2026-58196MEDIUMToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)EPSS 0.4%CVE-2026-58197HIGHToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movementEPSS 0.4%CVE-2026-54450LOWToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gatewayEPSS 0.3%CVE-2025-47274LOWToolHive stores secrets in the state store with no encryptionEPSS 0.1%