VulnSea

gocd vulnerabilities

CVEs whose affected-version data names the gocd package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-68919High· 7.0
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage …

Twilightgocd · gocdvia NVD
CVE-2026-55060Low· 3.7
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source c…

Sunlitgocd · gocdvia NVD
CVE-2026-52742Medium· 5.1
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for gro…

Sunlitgocd · gocdvia NVD
CVE-2026-52741High· 7.5
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(…

Twilightgocd · gocdvia NVD
CVE-2026-52740Medium· 5.3
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with no…

Sunlitgocd · gocdvia NVD
CVE-2026-52743Medium· 4.3
today

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…

Sunlitgocd · gocdvia NVD
gocd vulnerabilities (CVEs) · VulnSea