VulnSea

cloudflare has 11 CVEs on record between 2021 and 2025. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. Most affected products: github.com/cloudflare/cfrpki (7), github.com/cloudflare/circl (2), github.com/cloudflare/cloudflared (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
Last 90 days
0 prev 0

Products

  • github.com/cloudflare/cfrpki 7
  • github.com/cloudflare/circl 2
  • github.com/cloudflare/cloudflared 1
  • github.com/cloudflare/goflow/v3 1
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

cloudflare vulnerabilities

CVEs affecting cloudflare, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2025-8556Low· 3.7
1y ago

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

CIRCL-Fourq: Missing and wrong validation can lead to incorrect results

Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.48%via OSV
CVE-2023-1732Medium· 5.3
3y ago

Improper random reading in CIRCL

Improper random reading in CIRCL

Sunlitcloudflare · github.com/cloudflare/circlEPSS 0.39%via OSV
CVE-2023-1314High· 7.5
3y ago

cloudflared's Installer has Local Privilege Escalation Vulnerability

cloudflared's Installer has Local Privilege Escalation Vulnerability

Twilightcloudflare · github.com/cloudflare/cloudflaredEPSS 0.26%via OSV
CVE-2022-3616Medium· 5.4
3y ago

OctoRPKI crashes when max iterations is reached

OctoRPKI crashes when max iterations is reached

Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.43%via OSV
CVE-2022-2529High· 7.5
3y ago

Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package

Twilightcloudflare · github.com/cloudflare/goflow/v3EPSS 0.87%via OSV
CVE-2021-3911Medium· 4.2
4y ago

Misconfigured IP address field in ROA leads to OctoRPKI crash

Misconfigured IP address field in ROA leads to OctoRPKI crash

Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.91%via OSV
CVE-2021-3912Medium· 4.2
4y ago

OctoRPKI crashes when processing GZIP bomb returned via malicious repository

OctoRPKI crashes when processing GZIP bomb returned via malicious repository

Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.85%via OSV
CVE-2021-3908Medium· 5.9
4y ago

Infinite certificate chain depth results in OctoRPKI running forever

Infinite certificate chain depth results in OctoRPKI running forever

Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 0.73%via OSV
CVE-2021-3909Medium· 4.4
4y ago

Infinite open connection causes OctoRPKI to hang forever

Infinite open connection causes OctoRPKI to hang forever

Sunlitcloudflare · github.com/cloudflare/cfrpkiEPSS 1.6%via OSV
CVE-2021-3910High· 7.5
4y ago

NUL character in ROA causes OctoRPKI to crash

NUL character in ROA causes OctoRPKI to crash

Twilightcloudflare · github.com/cloudflare/cfrpkiEPSS 1.3%via OSV
CVE-2021-3761High· 7.5
5y ago

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

OctoRPKI lacks contextual out-of-bounds check when validating RPKI ROA maxLength values

Twilightcloudflare · github.com/cloudflare/cfrpkiEPSS 1.2%via OSV
cloudflare vulnerabilities (CVEs) · VulnSea