vectordotdev has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 8.7 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.7
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
vectordotdev vulnerabilities
CVEs affecting vectordotdev, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-77619High· 8.7Vector is a high-performance observability data pipeline
Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenti…
CVE-2026-77621Critical· 9.3Vector is a high-performance observability data pipeline
Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result without confining it to an intended directory. When an untrusted source s…
CVE-2026-77620High· 8.7Vector is a high-performance observability data pipeline
Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that ca…