| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-32828 | Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration | akuity | kargo | 中危 | - | 2026-03-20 00:39:26 | Deep Dive |
| CVE-2026-27112 | Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints | akuity | kargo | - | - | 2026-02-20 21:22:57 | Deep Dive |
| CVE-2026-27111 | Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints | akuity | kargo | - | - | 2026-02-20 21:17:07 | Deep Dive |
| CVE-2026-24748 | Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access | akuity | kargo | - | - | 2026-01-27 21:23:54 | Deep Dive |