VYPR

Lakefs

by Treeverse

Source repositories

CVEs (7)

  • CVE-2026-48026HigAug 7, 2026
    risk 0.50cvss 8.7epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML.…

  • CVE-2026-26187HigFeb 13, 2026
    risk 0.46cvss 8.1epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath…

  • CVE-2025-68671MedJan 15, 2026
    risk 0.35cvss 6.5epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network…

  • CVE-2025-27100MedFeb 21, 2025
    risk 0.35cvss 6.5epss 0.00

    lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue. This problem has been patched in version…

  • CVE-2024-43784MedNov 26, 2024
    risk 0.30cvss 5.7epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that…

  • CVE-2025-64179MedNov 6, 2025
    risk 0.27cvss 5.3epss 0.00

    lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows anyone to retrieve aggregate API usage counts. While no sensitive data is…

  • CVE-2026-66006MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including email, name, and company after setup completion. Attackers can POST to…