NetApp / Storagegrid
73 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-22056 | CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | LOW | 2.3 | Aug 28, 2026 |
| CVE-2026-22051 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful expl… | LOW | 2.3 | Apr 20, 2026 |
| CVE-2025-26517 | CVE-2025-26517 Privilege Escalation Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 5.4 | Sep 19, 2025 |
| CVE-2025-26516 | CVE-2025-26516 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 5.3 | Sep 19, 2025 |
| CVE-2025-26515 | CVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale) | HIGH | 7.5 | Sep 19, 2025 |
| CVE-2025-26514 | CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 6.4 | Sep 19, 2025 |
| CVE-2025-25292 | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential) | CRITICAL | 9.3 | Mar 12, 2025 |
| CVE-2025-25291 | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential) | CRITICAL | 9.3 | Mar 12, 2025 |
| CVE-2024-21994 | CVE-2024-21994 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 4.3 | Nov 8, 2024 |
| CVE-2024-21988 | CVE-2024-21988 SSH Cryptographic Implementation Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 5.3 | Jun 14, 2024 |
| CVE-2024-21984 | Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 6.9 | Feb 16, 2024 |
| CVE-2024-21983 | Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | MEDIUM | 6.5 | Feb 16, 2024 |
| CVE-2023-27318 | Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale) | HIGH | 7.5 | Feb 5, 2024 |
| CVE-2022-38734 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could l… | HIGH | 7.5 | Mar 2, 2023 |
| CVE-2022-23238 | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susc… | MEDIUM | 6.5 | Aug 9, 2022 |
| CVE-2022-37434 | zlib: heap-based buffer over-read and overflow in inflate() in inflate.c via a large gzip header extra field | CRITICAL | 9.8 | Aug 5, 2022 |
| CVE-2022-1678 | kernel: improper update of sock reference in TCP pacing can lead to memory leak | HIGH | 7.5 | May 25, 2022 |
| CVE-2022-0778 | Infinite loop in BN_mod_sqrt() reachable when parsing certificates | HIGH | 7.5 | Mar 15, 2022 |
| CVE-2022-23233 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial… | HIGH | 7.5 | Mar 4, 2022 |
| CVE-2022-23232 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled,… | MEDIUM | 4.9 | Mar 4, 2022 |
| CVE-2022-23773 | golang: cmd/go: misinterpretation of branch names can lead to incorrect access control | HIGH | 7.5 | Feb 11, 2022 |
| CVE-2022-23772 | golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString | HIGH | 7.5 | Feb 11, 2022 |
| CVE-2022-23806 | golang: crypto/elliptic: IsOnCurve returns true for invalid field elements | CRITICAL | 9.1 | Feb 11, 2022 |
| CVE-2021-27006 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escala… | MEDIUM | 4.4 | Dec 23, 2021 |
| CVE-2021-40438 KEV | mod_proxy SSRF | CRITICAL | 9.0 | Sep 16, 2021 |
Showing 1 to 25 of 73 CVEs