VulnSea

Concert vulnerabilities

CVEs whose affected-version data names the Concert package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-15915Medium· 6.2
yesterday

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

SunlitIBM · Concertvia NVD
CVE-2025-36084Medium· 5.9
yesterday

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

SunlitIBM · Concertvia NVD
CVE-2025-12767Medium· 5.3
yesterday

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

SunlitIBM · Concertvia NVD
CVE-2026-16426Medium· 6.5
yesterday

IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF)

IBM Concert 1.0.0 through 3.0.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other…

SunlitIBM · Concertvia NVD
CVE-2026-17472Critical· 9.6
yesterday

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.

MidnightIBM · Concertvia NVD
CVE-2026-17465Medium· 6.5
yesterday

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.

IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper enforcement of storage limits.

SunlitIBM · Concertvia NVD
CVE-2025-13044Medium· 6.2
5mo ago

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

Sunlitibm · concertEPSS 0.14%via NVD
Concert vulnerabilities (CVEs) · VulnSea