indy-node vulnerabilities
CVEs whose affected-version data names the indy-node package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2020-11093High· 7.5Hyperledger Indy's update process of a DID does not check who signs the request
Hyperledger Indy's update process of a DID does not check who signs the request
▾ Twilightindy-node · indy-nodeEPSS 1.2%via OSV
CVE-2020-11090High· 7.5Uncontrolled Resource Consumption in Indy Node
Uncontrolled Resource Consumption in Indy Node
▾ Twilightindy-node · indy-nodeEPSS 2.1%via OSV