Known Vulnerabilities for Anchor by Solana-foundation
Listed below are 10 of the newest known vulnerabilities associated with "Anchor" by "Solana-foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45137 json | Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, a... | Not Provided | 2026-05-27 | 2026-05-28 |
| CVE-2026-44692 json | Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic down... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-44587 json | CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_den... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-42769 json | Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Managemen... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-42765 json | Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole ch... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-42177 json | linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrom... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-41061 json | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40565 json | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40243 json | Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN dat... | Not Provided | 2026-05-06 | 2026-05-07 |
| CVE-2026-34950 json | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/s... | Not Provided | 2026-04-06 | 2026-04-06 |