Vulnerabilidades en nuclio
8 resultadosAnálisis Vexday
Nuclio apresenta exposição mínima com apenas 1 CVE registrado na base, sem atividade de exploração conhecida (KEV) e sem criticidades máximas identificadas. A vulnerabilidade associada (CWE-75) não representa risco imediato, e a ausência de publicações recentes sugere que o fornecedor não está sob pressão de descobertas novas.
CVE-2026-79756HIGHNuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platformEPSS 7.5%CVE-2026-29042HIGHNuclio Shell Runtime Command Injection Leading to Privilege EscalationEPSS 3.3%CVE-2026-79754HIGHNuclio: Kaniko build tempDir command injectionEPSS 0.7%CVE-2026-79755HIGHNuclio: Unauthenticated OS command injection via function namespace in docker ps --filter label (local Docker platform)EPSS 0.7%CVE-2026-52832MEDIUMNuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containerEPSS 0.6%CVE-2026-52833HIGHNuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCEEPSS 0.6%CVE-2026-52831HIGHNuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCEEPSS 0.5%CVE-2026-45730HIGHNuclio: Missing authorization on project write paths allows any authenticated user to modify or delete any projectEPSS 0.5%