Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Cloud Foundry — Vulnerabilities & Security Advisories 72

Browse all 72 CVE security advisories affecting Cloud Foundry. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Cloud Foundry is an open-source platform-as-a-service (PaaS) that enables developers to deploy, run, and scale applications across hybrid and multi-cloud environments. Its architecture, which relies on complex component interactions, has historically exposed it to diverse vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation. With seventy-one recorded CVEs, these flaws often stem from input validation errors or misconfigurations within its core components like the Diego scheduler and UAA authentication service. Security incidents have frequently involved unauthorized access to containerized workloads or exploitation of API endpoints, highlighting risks associated with its distributed nature. While the project maintains active security patches, the sheer volume of historical vulnerabilities underscores the complexity of securing its extensive ecosystem. Organizations must rigorously audit configurations and apply updates promptly to mitigate these persistent threats inherent in its open-source, community-driven development model.

CVE ID Title CVSS Severity Published
CVE-2026-41005 UAA accepts SAML Encrypted Assertions authentication bypass — UAA CWE-347 9.0 Critical 2026-06-11
CVE-2026-22734 Cloud Foundry UAA SAML 2.0 Signature Bypass — UUA CWE-290 8.6 High 2026-04-16
CVE-2025-22246 CVE-2025-22246 – UAA Private Key Exposure — UAA 3.0 Low 2025-05-13
CVE-2025-22216 CVE-2025-22216 UAA Missing Zone Validation — Cloud Foundry UAA 5.4 Medium 2025-01-31
CVE-2024-38826 CVE-2024-38826 Cloud Controller Denial of Service Attack — Cloud Foundry 6.5AI Medium AI 2024-11-11
CVE-2024-37082 Cloud Foundry 安全漏洞 — haproxy-boshrelease CWE-290 9.1 Critical 2024-07-03
CVE-2024-22279 GoRouter Denial of Service Attack — Routing Release CWE-444 5.9 Medium 2024-06-10
CVE-2023-34061 CVE-2023-34061 – Gorouter route pruning — Routing Release 7.5 High 2024-01-12
CVE-2023-34041 CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter — Routing 5.3 Medium 2023-09-08
CVE-2023-20885 CF workflows leak credentials in system audit logs — Notifications 6.5 Medium 2023-06-16
CVE-2020-5423 Cloud Controller is vulnerable to denial of service via YAML parsing — CAPI CWE-400 7.5 - 2020-12-02
CVE-2020-5422 UAA password may appear in BOSH System Metrics Server process arguments — BOSH System Metrics Server CWE-214 6.5 - 2020-10-02
CVE-2020-5420 Gorouter is vulnerable to DoS attack via invalid HTTP responses — Routing CWE-754 7.7 - 2020-09-03
CVE-2020-5418 Cloud Controller allows users with no roles to list droplets — CAPI CWE-863 4.3 - 2020-09-03
CVE-2020-5417 Cloud Controller may allow developers to claim sensitive routes — CAPI CWE-732 8.1 - 2020-08-21
CVE-2020-5416 CF clusters with NGINX in front of them may be vulnerable to DoS — Routing CWE-404 7.5 - 2020-08-21
CVE-2020-5402 UAA fails to check the state parameter when authenticating with external IDPs — UAA CWE-352 8.8 - 2020-02-27
CVE-2020-5401 Cloud Foundry GoRouter is vulnerable to cache poisoning — Routing CWE-393 - - 2020-02-27
CVE-2020-5400 Cloud Controller logs environment variables from app manifests — CAPI CWE-522 6.5 - 2020-02-27
CVE-2020-5399 CredHub does not properly enable TLS for MySQL database connections — CredHub CWE-319 8.7 - 2020-02-12
CVE-2019-11294 CAPI leaks service broker URLs and GUIDs to space developers — CAPI CWE-200 4.3 - 2019-12-19
CVE-2019-11293 UAA logs all query parameters with debug logging level — UAA Release CWE-532 6.5 - 2019-12-06
CVE-2019-11290 Cloud Foundry UAA logs query parameters in tomcat access file — UAA Release CWE-532 7.5 - 2019-11-25
CVE-2019-11289 A forged route service request using an invalid nonce can cause the gorouter to panic and crash — Routing CWE-20 8.6 - 2019-11-19
CVE-2019-11283 Password leak in smbdriver logs — SMB Volume CWE-532 8.8 - 2019-10-23
CVE-2019-11282 UAA is vulnerable to a Blind SCIM injection leading to information disclosure — UAA Release CWE-200 4.3 - 2019-10-23
CVE-2019-11279 Privilege Escalation via Scope Manipulation in UAA — UAA Release (OSS) CWE-77 8.8 - 2019-09-26
CVE-2019-11278 Privilege Escalation via Blind SCIM Injection in UAA — UAA Release (OSS) CWE-77 8.8 - 2019-09-26
CVE-2019-11277 Volume Services is vulnerable to an LDAP injection attack — CF NFS volume release CWE-90 8.1 - 2019-09-23
CVE-2019-11274 UAA SCIM Filter XSS — UAA Release (OSS) CWE-79 6.1 - 2019-08-09

This page lists every published CVE security advisory associated with Cloud Foundry. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.