VYPR
Vendor

Noobaa

Products
2
CVEs
3
Across products
4
Status
Private

Products

2

Recent CVEs

3
  • CVE-2026-86330HigSep 28, 2026
    risk 0.47cvss 7.2epss —

    An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is…

  • CVE-2026-94368HigSep 21, 2026
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to…

  • CVE-2021-3529HigJun 2, 2021
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response,…