CVE Browser

More filters (active)
CVE-2026-58197 HIGH

ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement

CVSS 8.8 EPSS 0.37% Sep 18, 2026
Go
CVE-2026-58196 LOW

ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation)

CVSS 2.9 EPSS 0.43% Sep 15, 2026
Go
CVE-2026-54450 LOW

ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway

CVSS 2.9 EPSS 0.33% Sep 15, 2026
Go
CVE-2025-47274 LOW

ToolHive stores secrets in the state store with no encryption

CVSS 2.4 EPSS 0.13% May 12, 2025
CVE-2024-37904 MEDIUM

Denial of service from maliciously configured Git repository in Minder

CVSS 5.7 EPSS 0.46% Jun 18, 2024
Go
CVE-2024-35238 MEDIUM

Denial of service of Minder Server from maliciously crafted GitHub attestations

CVSS 5.3 EPSS 0.53% May 27, 2024
Go
CVE-2024-35194 MEDIUM

Stacklok Minder vulnerable to denial of service from maliciously crafted templates

CVSS 5.3 EPSS 0.41% May 20, 2024
Go
CVE-2024-35185 MEDIUM

Denial of service of Minder Server with attacker-controlled REST endpoint

CVSS 5.3 EPSS 0.46% May 16, 2024
Go
CVE-2024-34084 HIGH

Minder's Github Webhook Handler vulnerable to denial of service from un-validated requests

CVSS 7.5 EPSS 0.59% May 7, 2024
Go
CVE-2024-31455 MEDIUM

Minder GetRepositoryByName data leak

CVSS 4.3 EPSS 0.77% Apr 9, 2024
Go
CVE-2024-27916 HIGH

`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated user

CVSS 7.1 EPSS 0.67% Mar 6, 2024
Go
CVE-2024-27093 HIGH

Minder trusts client-provided mapping from repo name to upstream ID

CVSS 7.5 EPSS 0.55% Feb 26, 2024
Go

Showing 1 to 12 CVEs · page 1