Browse all 7 CVE security advisories affecting CloudFoundry Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-41861 | Arbitrary Root File Write via Path Traversal in BOSH agent — BOSHCWE-22 | 4.2 | Medium | 2026-08-06 |
| CVE-2026-47840 | LDAP StartTLS unconditionally disables hostname verification — UAA | 7.5 | High | 2026-07-09 |
| CVE-2026-47829 | Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director — bosh-cli | - | - | 2026-07-09 |
| CVE-2026-47826 | blobs.yaml Path Traversal Allows File Writes — BOSH CLI tool | - | - | 2026-07-09 |
| CVE-2026-41013 | Tenant-controlled comma smuggles arbitrary CIFS mount options — smb-volume-releaseCWE-88 | - | - | 2026-06-01 |
| CVE-2026-22726 | Route Services Firewall Bypass — Routing releaseCWE-923 | 5.0 | Medium | 2026-04-30 |
| CVE-2026-22723 | UAA User Token Revocation logic error — UAA | 6.5 | Medium | 2026-03-05 |
This page lists every published CVE security advisory associated with CloudFoundry Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.