lf-edge has 5 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.5 (medium). None have a confirmed exploitation report. Most affected products: github.com/lf-edge/ekuiper/v2 (4), github.com/lf-edge/ekuiper (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- github.com/lf-edge/ekuiper/v2 4
- github.com/lf-edge/ekuiper 1
Worst active — by depth score
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names. 54CVE-2024-43406High· 8.8LF Edge eKuiper has a SQL Injection in sqlKvStore49CVE-2025-58363Medium· 5.5LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint30CVE-2025-24979Medium· 5.5LF Edge eKuiper: SSRF in External Service30CVE-2025-24978Low· 3.7LF Edge eKuiper: Self-XSS in External Service Creation20
lf-edge vulnerabilities
CVEs affecting lf-edge, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-24979Medium· 5.5LF Edge eKuiper: SSRF in External Service
LF Edge eKuiper: SSRF in External Service
CVE-2025-24978Low· 3.7LF Edge eKuiper: Self-XSS in External Service Creation
LF Edge eKuiper: Self-XSS in External Service Creation
CVE-2025-58363Medium· 5.5LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names.
eKuiper API endpoints handling SQL queries with user-controlled table names.
CVE-2024-43406High· 8.8LF Edge eKuiper has a SQL Injection in sqlKvStore
LF Edge eKuiper has a SQL Injection in sqlKvStore