keylime vulnerabilities
CVEs whose affected-version data names the keylime package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-1709Critical· 9.4A flaw was found in Keylime
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network ac…
▾ Midnightkeylime · keylimeEPSS 5.5%via NVD
CVE-2023-38201Medium· 6.5Keylime registrar and (untrusted) Agent can be bypassed by an attacker
Keylime registrar and (untrusted) Agent can be bypassed by an attacker
▾ Sunlitkeylime · keylimeEPSS 0.49%via OSV
CVE-2023-38200High· 7.5Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
▾ Twilightkeylime · keylimeEPSS 1.4%via OSV
CVE-2022-1053Critical· 9.1Tenant and Verifier might not use the same registrar data
Tenant and Verifier might not use the same registrar data
▾ Midnightkeylime · keylimeEPSS 1.4%via OSV