nuclio has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.0 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.0
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-52833High· 8.0Nuclio is a "Serverless" framework for Real-Time Events and Data Processing44CVE-2026-52831High· 8.0Nuclio is a "Serverless" framework for Real-Time Events and Data Processing44CVE-2026-52832Medium· 4.9Nuclio is a "Serverless" framework for Real-Time Events and Data Processing39
nuclio vulnerabilities
CVEs affecting nuclio, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-52833High· 8.0Nuclio is a "Serverless" framework for Real-Time Events and Data Processing
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runti…
CVE-2026-52832Medium· 4.9PoCNuclio is a "Serverless" framework for Real-Time Events and Data Processing
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:…
CVE-2026-52831High· 8.0⚖ disputedNuclio is a "Serverless" framework for Real-Time Events and Data Processing
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container…