Known Vulnerabilities for Pulp by Pulpproject
Listed below are 10 of the newest known vulnerabilities associated with "Pulp" by "Pulpproject".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90959 json | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users... | Not Provided | 2026-09-24 | 2026-09-30 |
| CVE-2026-84232 json | A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with the... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-79717 json | A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An auth... | Not Provided | 2026-08-25 | 2026-08-27 |
| CVE-2026-12701 json | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths d... | Not Provided | 2026-07-20 | 2026-07-22 |
| CVE-2018-10917 json | pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository... | 6.5 - MEDIUM | 2018-08-15 | 2023-02-12 |
| CVE-2018-1090 json | In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all... | 7.5 - HIGH | 2018-06-18 | 2019-10-09 |
| CVE-2016-3704 json | Not Provided | 2017-06-13 | 2025-04-20 | |
| CVE-2016-3696 json | Not Provided | 2017-06-13 | 2025-04-20 | |
| CVE-2016-3112 json | Not Provided | 2017-06-08 | 2025-04-20 | |
| CVE-2016-3111 json | Not Provided | 2017-06-08 | 2025-04-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pulpproject | Pulp | 2.9.3 | |||
| Application | Pulpproject | Pulp | 2.9.2 | |||
| Application | Pulpproject | Pulp | 2.9.1 | |||
| Application | Pulpproject | Pulp | 2.9.0 | |||
| Application | Pulpproject | Pulp | 2.8.7 | |||
| Application | Pulpproject | Pulp | 2.8.6 | |||
| Application | Pulpproject | Pulp | 2.8.5 | |||
| Application | Pulpproject | Pulp | 2.8.4 | |||
| Application | Pulpproject | Pulp | 2.8.3 | |||
| Application | Pulpproject | Pulp | 2.8.2-1 | |||
| Application | Pulpproject | Pulp | 2.8.2 | |||
| Application | Pulpproject | Pulp | 2.8.1 | |||
| Application | Pulpproject | Pulp | 2.8.0 | |||
| Application | Pulpproject | Pulp | 2.7.0 | |||
| Application | Pulpproject | Pulp | 2.6.5 | |||
| Application | Pulpproject | Pulp | 2.6.4 | |||
| Application | Pulpproject | Pulp | 2.6.3 | |||
| Application | Pulpproject | Pulp | 2.6.2 | |||
| Application | Pulpproject | Pulp | 2.6.1 | |||
| Application | Pulpproject | Pulp | 2.6.0 |