VYPR

Controller

by Opendaylight

Source repositories

CVEs (4)

  • CVE-2026-36500CriJun 5, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.

  • CVE-2024-37018CriMay 31, 2024
    risk 0.59cvss 9.1epss 0.00

    The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

  • CVE-2026-36501HigJun 5, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2017-1000411HigJan 31, 2018
    risk 0.49cvss 7.5epss 0.02

    OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown. If multiple different flows with…