fabric vulnerabilities
CVEs whose affected-version data names the fabric package (npm, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-69843Critical· 10.0Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70178High· 8.5Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVE-2026-63509Critical· 9.9Microsoft Fabric Elevation of Privilege Vulnerability
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVE-2026-44311Medium· 5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
CVE-2026-41586Critical· 9.8Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which cal…
CVE-2011-2185MediumFabric vulnerable to symlink attack on tmp files
Fabric vulnerable to symlink attack on tmp files