Sylabs / Singularity
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-47215 | Singularity: Incorrect path matching for 'limit container paths' directive | MEDIUM | 4.8 | Sep 15, 2026 |
| CVE-2025-64750 | Singluarity ineffectively applies of selinux / apparmor LSM process labels | MEDIUM | 4.5 | Dec 2, 2025 |
| CVE-2023-30549 | Unpatched extfs vulnerabilities are exploitable through suid-mode Apptainer | HIGH | 7.8 | Apr 25, 2023 |
| CVE-2021-33027 | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce. | CRITICAL | 9.8 | Jul 19, 2021 |
| CVE-2021-33622 | Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value. | CRITICAL | 9.8 | Jun 15, 2021 |
| CVE-2021-32635 | Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint | MEDIUM | 6.3 | May 28, 2021 |
| CVE-2021-29136 | Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci u… | MEDIUM | 5.5 | Apr 6, 2021 |
| CVE-2020-15229 | Path traversal and files overwrite with unsquashfs | CRITICAL | 9.3 | Oct 14, 2020 |
| CVE-2020-25040 | Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulner… | HIGH | 8.8 | Sep 16, 2020 |
| CVE-2020-25039 | Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. | HIGH | 8.1 | Sep 16, 2020 |
| CVE-2020-13846 | Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code. | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-13845 | Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fi… | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-13847 | Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header… | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2019-19724 | Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an informat… | HIGH | 7.5 | Dec 18, 2019 |
| CVE-2019-11328 | An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerab… | HIGH | 8.8 | May 14, 2019 |
| CVE-2018-19295 | Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks. | HIGH | 7.8 | Dec 17, 2018 |
| CVE-2018-12021 | Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a maliciou… | MEDIUM | 6.5 | Jul 5, 2018 |
Showing 1 to 17 of 17 CVEs