github.com/concourse/concourse vulnerabilities
CVEs whose affected-version data names the github.com/concourse/concourse package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-49826LowConcourse is a container-based automation system written in Go
Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in…
▾ Sunlitconcourse · github.com/concourse/concourseEPSS 0.30%via NVD
CVE-2022-31683Medium· 5.4Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
▾ Sunlitconcourse · github.com/concourse/concourseEPSS 0.45%via OSV
CVE-2020-5415High· 7.5GitLab auth uses full name instead of username as user ID, allowing impersonation
GitLab auth uses full name instead of username as user ID, allowing impersonation
▾ Twilightconcourse · github.com/concourse/concourseEPSS 1.2%via OSV