VYPR

Coverity

by Black Duck

CVEs (2)

  • CVE-2026-1496CriMar 27, 2026
    risk 0.60cvss epss 0.00

    Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can…

  • CVE-2026-8339HigJul 29, 2026
    risk 0.00cvss epss 0.00

    A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized…