Redocly has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.1 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Redocly vulnerabilities
CVEs affecting Redocly, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-63325High· 7.8Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descript…
▾ TwilightRedocly · redocly-cliEPSS 0.22%via NVD
CVE-2026-63225Medium· 4.4Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…
▾ SunlitRedocly · redocly-cliEPSS 0.18%via NVD