Projectcontour / Contour
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-50149 | Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled | MEDIUM | 6.5 | Aug 19, 2026 |
| CVE-2026-41246 | Contour: Lua code injection via Cookie Path Rewrite Policy | HIGH | 8.1 | Apr 23, 2026 |
| CVE-2024-36539 | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | CRITICAL | 9.8 | Jul 24, 2024 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2021-32783 | Authorization bypass in Contour | HIGH | 8.5 | Jul 23, 2021 |
| CVE-2020-15127 | Denial of service in Contour | HIGH | 7.5 | Aug 5, 2020 |
Showing 1 to 6 of 6 CVEs