Uber
Products
2- 3 CVEs
- 1 CVE
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-75625 | Cri | 0.59 | 9.0 | 0.00 | Aug 18, 2026 | Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply… | ||
| CVE-2022-47747 | Hig | 0.49 | 7.5 | 0.01 | Jan 20, 2023 | kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs. | ||
| CVE-2017-13104 | Hig | 0.49 | 7.5 | 0.01 | Aug 15, 2018 | Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. | ||
| CVE-2026-92791 | Hig | 0.42 | 7.5 | 0.01 | Sep 16, 2026 | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary… |
- risk 0.59cvss 9.0epss 0.00
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply…
- risk 0.49cvss 7.5epss 0.01
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
- risk 0.49cvss 7.5epss 0.01
Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
- risk 0.42cvss 7.5epss 0.01
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary…