juju has 3 CVEs on record between 2024 and 2026. The median CVSS is 8.8 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Products
- github.com/juju/juju 3
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-4370Critical· 10.0Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster55CVE-2025-53513High· 8.8Juju zip slip vulnerability via authenticated endpoint49CVE-2024-6984High· 8.8Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm48
juju vulnerabilities
CVEs affecting juju, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-4370Critical· 10.0Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
▾ Midnightjuju · github.com/juju/jujuEPSS 0.38%via OSV
CVE-2025-53513High· 8.8Juju zip slip vulnerability via authenticated endpoint
Juju zip slip vulnerability via authenticated endpoint
▾ Twilightjuju · github.com/juju/jujuEPSS 0.66%via OSV
CVE-2024-6984High· 8.8Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm
▾ Twilightjuju · github.com/juju/jujuEPSS 0.38%via OSV