frigate vulnerabilities
CVEs whose affected-version data names the frigate package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-75608High· 7.7Frigate is an open source network video recorder
Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for G…
CVE-2026-75607High· 8.1PoCFrigate is an open source network video recorder
Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking the authenticated user's role because the nginx …
CVE-2026-33125High· 7.1Frigte has broken access control viewer user can delete admin and other users account
Frigte has broken access control viewer user can delete admin and other users account
CVE-2024-32874Critical· 9.3Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service