gocd has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 5.2 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-863 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.2
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-52741High· 7.5GoCD is a continuous deliver server41CVE-2026-68919High· 7.0GoCD is a continuous deliver server39CVE-2026-52740Medium· 5.3GoCD is a continuous deliver server29CVE-2026-52742Medium· 5.1GoCD is a continuous deliver server28CVE-2026-52743Medium· 4.3GoCD is a continuous deliver server24
gocd vulnerabilities
CVEs affecting gocd, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-68919High· 7.0GoCD is a continuous deliver server
GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage …
CVE-2026-55060Low· 3.7GoCD is a continuous deliver server
GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source c…
CVE-2026-52742Medium· 5.1GoCD is a continuous deliver server
GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for gro…
CVE-2026-52741High· 7.5GoCD is a continuous deliver server
GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(…
CVE-2026-52740Medium· 5.3GoCD is a continuous deliver server
GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with no…
CVE-2026-52743Medium· 4.3GoCD is a continuous deliver server
GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…