salt has 15 CVEs on record between 2022 and 2026. The median CVSS is 6.7 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.7
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- salt 15
Worst active — by depth score
CVE-2017-12791Critical· 9.8SaltStack Salt Directory traversal vulnerability in minion id validation55CVE-2025-22239High· 8.1Salt vulnerable to arbitrary event injection45CVE-2025-22236High· 8.1Salt has minion event bus authorization bypass vulnerability45CVE-2013-2228High· 8.1SaltStack RSA Key Generation allows remote users to decrypt communications45CVE-2025-62348High· 7.8Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload43
salt vulnerabilities
CVEs affecting salt, newest first. Open any entry for full detail, references, and exploit status.
15 CVEsRSS
CVE-2025-62349Medium· 6.2Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation
CVE-2025-62348High· 7.8Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
CVE-2025-22240Medium· 6.3Salt allows arbitrary directory creation or file deletion
Salt allows arbitrary directory creation or file deletion
CVE-2025-22238Medium· 4.2Salt vulnerable to directory traversal attack in minion file cache creation
Salt vulnerable to directory traversal attack in minion file cache creation
CVE-2025-22236High· 8.1Salt has minion event bus authorization bypass vulnerability
Salt has minion event bus authorization bypass vulnerability
CVE-2025-22237Medium· 6.7Salt's on demand pillar functionality vulnerable to arbitrary command injections
Salt's on demand pillar functionality vulnerable to arbitrary command injections
CVE-2025-22239High· 8.1Salt vulnerable to arbitrary event injection
Salt vulnerable to arbitrary event injection
CVE-2025-22242Medium· 5.6Salt's worker process vulnerable to denial of service through file read operation
Salt's worker process vulnerable to denial of service through file read operation
CVE-2025-22241Medium· 5.6Salt's file contents overwrite the VirtKey class
Salt's file contents overwrite the VirtKey class
CVE-2024-38825Medium· 6.4Salt's salt.auth.pki module does not properly authenticate callers
Salt's salt.auth.pki module does not properly authenticate callers
CVE-2023-34049Medium· 6.7Salt preflight script could be attacker controlled
Salt preflight script could be attacker controlled
CVE-2024-22231Medium· 5.0Directory creation by malicious user in saltstack
Directory creation by malicious user in saltstack
CVE-2024-22232High· 7.7Path traversal in saltstack
Path traversal in saltstack
CVE-2017-12791Critical· 9.8SaltStack Salt Directory traversal vulnerability in minion id validation
SaltStack Salt Directory traversal vulnerability in minion id validation
CVE-2013-2228High· 8.1SaltStack RSA Key Generation allows remote users to decrypt communications
SaltStack RSA Key Generation allows remote users to decrypt communications