Known Vulnerabilities for Discovery by Puppet
Listed below are 2 of the newest known vulnerabilities associated with "Discovery" by "Puppet".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104422 json | The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig an... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-104056 json | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103957 json | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-102511 json | Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-102508 json | Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PL... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-101058 json | python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual po... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-100289 json | Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authentica... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-97910 json | In the Linux kernel, the following vulnerability has been resolved: ASoC: sprd: validate compress buffer sizes against fixed... | Not Provided | 2026-09-25 | 2026-09-25 |
| CVE-2026-96257 json | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the ... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-93247 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL derefe... | Not Provided | 2026-09-24 | 2026-09-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Puppet | Discovery | 1.9.0 | |||
| Application | Puppet | Discovery | 1.8.0 | |||
| Application | Puppet | Discovery | 1.7.0 | |||
| Application | Puppet | Discovery | 1.6.0 | |||
| Application | Puppet | Discovery | 1.5.0 | |||
| Application | Puppet | Discovery | 1.4.1 | |||
| Application | Puppet | Discovery | 1.4.0 | |||
| Application | Puppet | Discovery | 1.3.0 | |||
| Application | Puppet | Discovery | 1.2.0 | |||
| Application | Puppet | Discovery | 1.1.0 | |||
| Application | Puppet | Discovery | 1.0.1 | |||
| Application | Puppet | Discovery | 1.0.0 |