VulnSea

salt has 15 CVEs on record between 2022 and 2026. The median CVSS is 6.7 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.7
Publish → KEV
Last 90 days
0 prev 0

Products

  • salt 15
15
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

salt vulnerabilities

CVEs affecting salt, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2025-62349Medium· 6.2
7mo ago

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

Sunlitsalt · saltEPSS 0.43%via OSV
CVE-2025-62348High· 7.8
7mo ago

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Twilightsalt · saltEPSS 0.19%via OSV
CVE-2025-22240Medium· 6.3
1y ago

Salt allows arbitrary directory creation or file deletion

Salt allows arbitrary directory creation or file deletion

Sunlitsalt · saltEPSS 0.16%via OSV
CVE-2025-22238Medium· 4.2
1y ago

Salt vulnerable to directory traversal attack in minion file cache creation

Salt vulnerable to directory traversal attack in minion file cache creation

Sunlitsalt · saltEPSS 0.29%via OSV
CVE-2025-22236High· 8.1
1y ago

Salt has minion event bus authorization bypass vulnerability

Salt has minion event bus authorization bypass vulnerability

Twilightsalt · saltEPSS 0.17%via OSV
CVE-2025-22237Medium· 6.7
1y ago

Salt's on demand pillar functionality vulnerable to arbitrary command injections

Salt's on demand pillar functionality vulnerable to arbitrary command injections

Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2025-22239High· 8.1
1y ago

Salt vulnerable to arbitrary event injection

Salt vulnerable to arbitrary event injection

Twilightsalt · saltEPSS 0.18%via OSV
CVE-2025-22242Medium· 5.6
1y ago

Salt's worker process vulnerable to denial of service through file read operation

Salt's worker process vulnerable to denial of service through file read operation

Sunlitsalt · saltEPSS 0.14%via OSV
CVE-2025-22241Medium· 5.6
1y ago

Salt's file contents overwrite the VirtKey class

Salt's file contents overwrite the VirtKey class

Sunlitsalt · saltEPSS 0.18%via OSV
CVE-2024-38825Medium· 6.4
1y ago

Salt's salt.auth.pki module does not properly authenticate callers

Salt's salt.auth.pki module does not properly authenticate callers

Sunlitsalt · saltEPSS 0.15%via OSV
CVE-2023-34049Medium· 6.7
1y ago

Salt preflight script could be attacker controlled

Salt preflight script could be attacker controlled

Sunlitsalt · saltEPSS 0.19%via OSV
CVE-2024-22231Medium· 5.0
2y ago

Directory creation by malicious user in saltstack

Directory creation by malicious user in saltstack

Sunlitsalt · saltEPSS 0.69%via OSV
CVE-2024-22232High· 7.7
2y ago

Path traversal in saltstack

Path traversal in saltstack

Twilightsalt · saltEPSS 0.84%via OSV
CVE-2017-12791Critical· 9.8
4y ago

SaltStack Salt Directory traversal vulnerability in minion id validation

SaltStack Salt Directory traversal vulnerability in minion id validation

Midnightsalt · saltEPSS 4.1%via OSV
CVE-2013-2228High· 8.1
4y ago

SaltStack RSA Key Generation allows remote users to decrypt communications

SaltStack RSA Key Generation allows remote users to decrypt communications

Twilightsalt · saltEPSS 2.0%via OSV
salt vulnerabilities (CVEs) · VulnSea