Security Risk Category

DevOps Security Risks

Published vulnerability pages connected to DevOps. Each page keeps one canonical URL and focused remediation guidance.

81 published DevOps risks

DevOps risks

Showing 1–36 of 81 published risks.

high

CVE-2026-65906 TeamCity vulnerability

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

CVE-2026-65906devopsremote-code-execution

Updated Jul 24, 2026

critical

CVE-2026-65907 TeamCity vulnerability

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

CVE-2026-65907devopsremote-code-execution

Updated Jul 24, 2026

high

CVE-2026-65908 PyCharm vulnerability

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CVE-2026-65908pythondevopssupply-chainremote-code-execution

Updated Jul 24, 2026

low

CVE-2023-37508 DevOps Plan vulnerability

HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an attacker to exploit this vulnerability if certain browser weaknesses are present.

CVE-2023-37508browserdevopsxss

Updated Jul 21, 2026

medium

CVE-2023-37507 DevOps Plan vulnerability

HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

CVE-2023-37507devopsinformation-disclosure

Updated Jul 21, 2026

lowEPSS 0.002

CVE-2026-41579 runc /dev Symlink Host File Modification Vulnerability

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0.

CVE-2026-41579linuxcloud-securitydevopssupply-chain

Updated Jul 15, 2026

criticalEPSS 0.002

CVE-2026-53488 containerd CRI Label Validation Command Execution Risk

containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.

CVE-2026-53488cloud-securitydevopssupply-chainremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-33382 in Grafana OSS

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVE-2026-33382api-securitydevopsweb-applicationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-8595 in Grafana OSS

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVE-2026-8595browserdevopsweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-8609 in Grafana OSS

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVE-2026-8609devopsweb-applicationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5135 in Red Hat Satellite

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.

CVE-2026-5135linuxdevopsweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5138 in Red Hat Satellite

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.

CVE-2026-5138linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-5142 in Red Hat Satellite

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

CVE-2026-5142linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

high

CVE-2026-24240 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24240pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-24242 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2026-24242pythonlinuxdevopsinformation-disclosure

Updated Jul 15, 2026

high

CVE-2026-24243 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24243pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-24244 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24244pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-24245 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24245pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24246 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24246pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24247 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24247pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24248 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24248pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24249 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24249pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24250 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24250pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24251 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24251pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-24264 in NVIDIA Triton Inference Server

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service.

CVE-2026-24264linuxdevopsinput-validationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-24266 in NVIDIA Triton Inference Server

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.

CVE-2026-24266linuxdevopsdenial-of-servicememory-corruption

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-49087 in Kibana

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render Kibana unavailable.

CVE-2026-49087devopsweb-applicationdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-49088 in Kibana

Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may be accessible to operators with log access.

CVE-2026-49088devopsweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56148 in Elasticsearch

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the affected node unavailable.

CVE-2026-56148api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56149 in Elasticsearch

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption, which may render the affected node unavailable.

CVE-2026-56149api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56150 in Elastic Fleet Server

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may render Fleet Server unavailable.

CVE-2026-56150api-securitydevopsdenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-56151 in Kibana

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy management functionality unavailable.

CVE-2026-56151devopsweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58065 in Apache Airflow Providers Git

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.

CVE-2026-58065pythonnetwork-securitydevopssupply-chain

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-59245 in Apache Airflow Providers FAB

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.

CVE-2026-59245pythondevopsauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-46680 in containerd

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVE-2026-46680cloud-securitydevopsprivilege-escalation

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-47262 in containerd

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.

CVE-2026-47262api-securitycloud-securitydevopsdenial-of-service

Updated Jul 15, 2026