VYPR

prowler

by Prowler Cloud

Source repositories

CVEs (4)

  • CVE-2026-73263CriAug 12, 2026
    risk 0.57cvss 9.9epss 0.00

    Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in…

  • CVE-2026-59151CriJul 10, 2026
    risk 0.55cvss 9.6epss 0.00

    Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the…

  • CVE-2026-73264HigAug 12, 2026
    risk 0.42cvss 7.6epss 0.00

    Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST…

  • CVE-2026-73262MedAug 12, 2026
    risk 0.28cvss 5.4epss 0.00

    Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who…