Known Vulnerabilities for Bosh by Cloud Foundry
Listed below are 5 of the newest known vulnerabilities associated with "Bosh" by "Cloud Foundry".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41860 json | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestH... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-41859 json | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or ... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-41858 json | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-rele... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-41704 json | AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every respons... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-41011 json | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and ... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-41010 json | ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{nam... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-41009 json | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inj... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2019-11271 json | Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when c... | 7.8 - HIGH | 2019-06-19 | 2020-10-16 |
| CVE-2018-11083 json | Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to ... | 8.1 - HIGH | 2018-10-05 | 2020-01-17 |
| CVE-2017-4961 json | Not Provided | 2017-06-13 | 2025-04-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloud Foundry | Bosh | 270.3.0 | |||
| Application | Cloud Foundry | Bosh | 270.2.0 | |||
| Application | Cloud Foundry | Bosh | 270.1.1 | |||
| Application | Cloud Foundry | Bosh | 270.1.0 | |||
| Application | Cloud Foundry | Bosh | 270.0.0 | |||
| Application | Cloud Foundry | Bosh | 269.0.1 | |||
| Application | Cloud Foundry | Bosh | 269.0.0 | |||
| Application | Cloud Foundry | Bosh | 268.7.0 | |||
| Application | Cloud Foundry | Bosh | 268.6.0 | |||
| Application | Cloud Foundry | Bosh | 268.5.0 | |||
| Application | Cloud Foundry | Bosh | 268.4.0 | |||
| Application | Cloud Foundry | Bosh | 268.3.0 | |||
| Application | Cloud Foundry | Bosh | 268.2.1 | |||
| Application | Cloud Foundry | Bosh | 268.2.0 | |||
| Application | Cloud Foundry | Bosh | 268.1.0 | |||
| Application | Cloud Foundry | Bosh | 268.0.1 | |||
| Application | Cloud Foundry | Bosh | 267.8.0 | |||
| Application | Cloud Foundry | Bosh | 267.7.0 | |||
| Application | Cloud Foundry | Bosh | 267.6.0 | |||
| Application | Cloud Foundry | Bosh | 267.5.0 |