github.com/lf-edge/ekuiper/v2 vulnerabilities
CVEs whose affected-version data names the github.com/lf-edge/ekuiper/v2 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2025-24979Medium· 5.5LF Edge eKuiper: SSRF in External Service
LF Edge eKuiper: SSRF in External Service
▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-24978Low· 3.7LF Edge eKuiper: Self-XSS in External Service Creation
LF Edge eKuiper: Self-XSS in External Service Creation
▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-58363Medium· 5.5LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names.
eKuiper API endpoints handling SQL queries with user-controlled table names.
▾ Twilightlf-edge · github.com/lf-edge/ekuiper/v2EPSS 0.77%via OSV