Known Vulnerabilities for CF Deployment by Cloud Foundry
Listed below are 10 of the newest known vulnerabilities associated with "CF Deployment" by "Cloud Foundry".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-85199 json | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-control... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-84736 json | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator com... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-84365 json | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix rele... | Not Provided | 2026-09-01 | 2026-09-04 |
| CVE-2026-84175 json | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supp... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-82859 json | hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protec... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-82855 json | @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-gover... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-82241 json | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/1... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-81526 json | The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in ... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-80561 json | In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() ... | Not Provided | 2026-08-26 | 2026-08-27 |
| CVE-2026-80557 json | In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing b... | Not Provided | 2026-08-26 | 2026-08-27 |