Vendor
Operator Foundry
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-87049 | imp | 0.57 | 8.7 | — | Sep 8, 2026 | operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events | ||
| CVE-2026-87050 | mod | 0.27 | 4.2 | — | Sep 8, 2026 | operator-foundry: operator-foundry: GitHub Actions and reusable workflow not pinned to commit SHA | ||
| CVE-2026-87052 | low | 0.17 | 2.6 | — | Sep 8, 2026 | operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration | ||
| CVE-2026-87051 | low | 0.17 | 2.6 | — | Sep 8, 2026 | operator-foundry: operator-foundry: resolveAndValidatePath performs lexical containment only — symlinks can escape the build context |
- risk 0.57cvss 8.7epss —
operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events
- risk 0.27cvss 4.2epss —
operator-foundry: operator-foundry: GitHub Actions and reusable workflow not pinned to commit SHA
- risk 0.17cvss 2.6epss —
operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration
- risk 0.17cvss 2.6epss —
operator-foundry: operator-foundry: resolveAndValidatePath performs lexical containment only — symlinks can escape the build context