VulnSea

cloudfoundry has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 8.3 (high), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.3
Publish → KEV
Last 90 days
4 prev 0

Weakness classes

Products

  • bosh_cli 4
4
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

cloudfoundry vulnerabilities

CVEs affecting cloudfoundry, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-47829High· 7.8
2mo ago

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to lo…

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to lo…

Twilightcloudfoundry · bosh_cliEPSS 0.42%via NVD
CVE-2026-47828High· 8.8
2mo ago

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoin…

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoin…

Twilightcloudfoundry · bosh_cliEPSS 0.29%via NVD
CVE-2026-47826Critical· 9.1
2mo ago

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Midnightcloudfoundry · bosh_cliEPSS 0.55%via NVD
CVE-2026-41857High· 7.8
2mo ago

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

Twilightcloudfoundry · bosh_cliEPSS 0.23%via NVD
cloudfoundry vulnerabilities (CVEs) · VulnSea