Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Google Cloud — Vulnerabilities & Security Advisories 56

Browse all 56 CVE security advisories affecting Google Cloud. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Google Cloud operates as a comprehensive suite of cloud computing services, providing infrastructure, platform, and software solutions for enterprise data storage, analytics, and application development. With thirty-one recorded Common Vulnerabilities and Exposures, the platform has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex integration points or third-party dependencies. Security assessments indicate that while the underlying infrastructure maintains robust isolation mechanisms, application-layer vulnerabilities frequently arise from misconfigurations or unpatched components within managed services. Notable incidents have primarily involved data exposure risks due to incorrect access controls rather than systemic infrastructure breaches. The platform continues to implement rigorous patch management and automated security scanning to mitigate these risks, emphasizing the importance of proper configuration by end-users to maintain the integrity of deployed workloads within the broader Google ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-2472 Stored Cross-Site Scripting (XSS) in Vertex AI Python SDK Visualization — Vertex AI SDK for Python CWE-79 6.1AI Medium AI 2026-02-20
CVE-2026-1727 Information Disclosure via Bucket Squatting in Google Cloud Agentspace. — Gemini Enterprise (formerly Agentspace) CWE-200 7.5AI High AI 2026-02-06
CVE-2025-13427 Authentication Bypass in Dialogflow CX Messenger — Dialogflow CX Messenger CWE-287 9.1AI Critical AI 2025-12-18
CVE-2025-12952 Privilege Escalation in Dialogflow CX via Webhook Admin Role — Dialogflow CX CWE-269 8.8AI High AI 2025-12-10
CVE-2025-9571 Arbitrary Code Execution in Google Cloud Data Fusion via Malicious Artifact Upload — Cloud Data Fusion CWE-502 8.8AI High AI 2025-12-10
CVE-2025-13428 RCE in SecOps SOAR server via user-provided Python packages — Google Cloud SecOps SOAR CWE-20 8.8AI High AI 2025-12-09
CVE-2025-13292 Improper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access. — Apigee-X CWE-269 9.1 - 2025-12-06
CVE-2025-13426 Improper Sandboxing in Google Apigee's JavaCallout Policy Allows for Remote Code Execution — Apigee hybrid Javacallout policy CWE-913 8.8 - 2025-12-05
CVE-2025-12742 Remote Code Execution in Looker via Teradata JDBC Driver — Looker CWE-78 8.8AI High AI 2025-11-25
CVE-2025-12741 Arbitrary File Write in Denodo dialect of Looker allows Remote Code Execution — Looker CWE-20 8.8AI High AI 2025-11-24
CVE-2025-12740 Remote Command Execution in Looker via IBM DB2 JDBC drive — Looker CWE-20 8.8AI High AI 2025-11-24
CVE-2025-12739 Cross-Site Scripting (XSS) in Looker's Extension Loader leading to Admin Account Compromise — Looker CWE-79 7.6AI High AI 2025-11-24
CVE-2025-12414 Looker account compromise via punycode homograph attack — Looker CWE-290 7.4 - 2025-11-20
CVE-2025-12743 SQL Injection in Looker Project Generation Endpoint Allows Access to Internal MySQL Database — Looker CWE-89 6.5AI Medium AI 2025-11-19
CVE-2025-12472 Remote Code Execution in Looker due to Improperly Validated Directory Deletion — Looker CWE-362 7.5AI High AI 2025-11-19
CVE-2025-12405 Unauthorized access through stored credentials in Looker Studio — Looker Studio CWE-269 8.8 - 2025-11-10
CVE-2025-12409 SQL Injection in Looker Studio — Looker Studio CWE-89 8.1 - 2025-11-10
CVE-2025-12397 SQL Injection in Looker Studio — Looker Studio CWE-89 8.8 - 2025-11-10
CVE-2025-12155 Command Injection in Looker — Looker CWE-77 8.8 - 2025-11-10
CVE-2025-11915 HTTP Desynchronisation in Vertex AI for certain third-party models — Vertex AI: Partner Models for MaaS CWE-444 9.8AI Critical AI 2025-10-22
CVE-2025-9918 Zip Slip in Google SecOps SOAR allows for Remote Code Execution — Google SecOps SOAR CWE-22 8.8AI High AI 2025-09-11
CVE-2025-9118 Dataform Path Traversal — Dataform CWE-22 9.1AI Critical AI 2025-08-25
CVE-2025-4600 HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding Validation — Classic Application Load Balancer CWE-444 7.5AI High AI 2025-05-16
CVE-2025-0982 Sandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine) — Application Integration CWE-829 10.0 - 2025-02-06
CVE-2024-9858 Insecure user permissions in Google Cloud Migrate to Containers for Windows — Migrate to Containers CWE-276 6.7 - 2024-10-16
CVE-2024-5166 Insecure Direct Object Reference In Looker — Looker CWE-639 6.5 Medium 2024-05-22

This page lists every published CVE security advisory associated with Google Cloud. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.