Known Vulnerabilities for Bosh by Cloud Foundry
Listed below are 5 of the newest known vulnerabilities associated with "Bosh" by "Cloud Foundry".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-47831 json | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-build... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-47830 json | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authe... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-47829 json | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawne... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-47828 json | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's ... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-47827 json | Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands v... | Not Provided | 2026-08-21 | 2026-08-22 |
| CVE-2026-47826 json | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrat... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-41861 json | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with parti... | Not Provided | 2026-08-06 | 2026-08-07 |
| CVE-2026-41857 json | A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-41704 json | Not Provided | 2026-05-27 | 2026-06-08 | |
| CVE-2026-41012 json | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter... | Not Provided | 2026-08-29 | 2026-08-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloud Foundry | Bosh | 270.3.0 | |||
| Application | Cloud Foundry | Bosh | 270.2.0 | |||
| Application | Cloud Foundry | Bosh | 270.1.1 | |||
| Application | Cloud Foundry | Bosh | 270.1.0 | |||
| Application | Cloud Foundry | Bosh | 270.0.0 | |||
| Application | Cloud Foundry | Bosh | 269.0.1 | |||
| Application | Cloud Foundry | Bosh | 269.0.0 | |||
| Application | Cloud Foundry | Bosh | 268.7.0 | |||
| Application | Cloud Foundry | Bosh | 268.6.0 | |||
| Application | Cloud Foundry | Bosh | 268.5.0 | |||
| Application | Cloud Foundry | Bosh | 268.4.0 | |||
| Application | Cloud Foundry | Bosh | 268.3.0 | |||
| Application | Cloud Foundry | Bosh | 268.2.1 | |||
| Application | Cloud Foundry | Bosh | 268.2.0 | |||
| Application | Cloud Foundry | Bosh | 268.1.0 | |||
| Application | Cloud Foundry | Bosh | 268.0.1 | |||
| Application | Cloud Foundry | Bosh | 267.8.0 | |||
| Application | Cloud Foundry | Bosh | 267.7.0 | |||
| Application | Cloud Foundry | Bosh | 267.6.0 | |||
| Application | Cloud Foundry | Bosh | 267.5.0 |