VYPR
Vendor

Nuclio

Products
1
CVEs
8
Across products
8
Status
Private

Products

1

Recent CVEs

8
  • CVE-2026-29042CriMar 6, 2026
    risk 0.57cvss 9.8epss 0.03

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime…

  • CVE-2026-79756HigSep 2, 2026
    risk 0.50cvss —epss 0.08

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added validateFunctionName for function names and…

  • CVE-2026-45730HigSep 2, 2026
    risk 0.47cvss 8.3epss 0.00

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization…

  • CVE-2026-79755HigSep 2, 2026
    risk 0.45cvss 8.0epss 0.01

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=nuclio.io/namespace=" command…

  • CVE-2026-52833HigSep 2, 2026
    risk 0.45cvss 8.0epss 0.01

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with…

  • CVE-2026-52831HigSep 2, 2026
    risk 0.45cvss 8.0epss 0.01

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, ). Two fields in…

  • CVE-2026-79754HigSep 2, 2026
    risk 0.39cvss —epss 0.01

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.build.tempDir field before using it to construct a shell command. When the Kaniko container…

  • CVE-2026-52832MedSep 2, 2026
    risk 0.25cvss 4.9epss 0.01

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:myfunction) is parsed by…