github.com/juju/juju vulnerabilities
CVEs whose affected-version data names the github.com/juju/juju package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-4370Critical· 10.0Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
▾ Midnightjuju · github.com/juju/jujuEPSS 0.38%via OSV
CVE-2025-53513High· 8.8Juju zip slip vulnerability via authenticated endpoint
Juju zip slip vulnerability via authenticated endpoint
▾ Twilightjuju · github.com/juju/jujuEPSS 0.66%via OSV
CVE-2024-6984High· 8.8Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
▾ Twilightjuju · github.com/juju/jujuEPSS 0.38%via OSV