multicluster-engine/cloudevents-conductor-rhel9 vulnerabilities
CVEs whose affected-version data names the multicluster-engine/cloudevents-conductor-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-71297Medium· 5.4A flaw was found in the maestro gRPC broker
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading…
CVE-2026-71299Medium· 6.5A flaw was found in Maestro
A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumer…
CVE-2026-71298Medium· 6.4A flaw was found in maestro
A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extr…