VYPR
Vendor

Oxide

Products
4
CVEs
6
Across products
8
Status
Private

Products

4

Recent CVEs

6
  • CVE-2023-50913CriDec 5, 2024
    risk 0.59cvss 9.1epss 0.00

    Oxide control plane software before 5 allows SSRF.

  • CVE-2026-52834HigAug 19, 2026
    risk 0.40cvss 7.3epss 0.00

    jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid arithmetic. A 65536 x 65536 frame can…

  • CVE-2024-55582MedDec 9, 2024
    risk 0.37cvss 5.7epss 0.00

    Oxide before 6 has unencrypted Control Plane datastores.

  • CVE-2025-66432MedNov 30, 2025
    risk 0.33cvss 5.0epss 0.00

    In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

  • CVE-2016-1586LowApr 22, 2019
    risk 0.12cvss 1.8epss 0.01

    A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

  • CVE-2015-1317Apr 8, 2015
    risk 0.00cvss —epss 0.03

    Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.