VYPR

nebula

by Vesoft Inc

CVEs (3)

  • CVE-2026-81032CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status…

  • CVE-2024-47219CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

  • CVE-2024-47218CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.