Octopus Deploy

First CVE: Jun 17, 2021Active for: 5 years
68
CVEs Published
More CVEs Published than 65% of tracked CNAs
11.3
Avg CVEs / Year
More Avg CVEs / Year than 57% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Octopus Deploy as a CNA, 98.5% affect products that Octopus Deploy develops as a vendor.

98.5%
Self-reported: 67Third-party: 1

Of all the CVEs published that affect products developed by Octopus Deploy, 64.4% are self-published by Octopus Deploy as a CNA.

64.4%
35.6%
Self-published: 67Published by other CNAs: 37

Trends Over Time

The number and severity of CVEs published by Octopus Deploy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2021
5 years ago
Most Recent CVE
Jul 24, 2026
2 days ago

Top CVEs

All CVEs published by Octopus Deploy as a CNA, regardless of affected vendor or product.

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still v
Nov 1, 20229.830NONO
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
Sep 30, 20229.830NONO
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate ver
Sep 22, 20219.830NONO
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentiall
Feb 25, 20269.129NONO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Inject
Sep 30, 20249.829NONO
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
Oct 27, 20229.128NONO
In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpo
Jun 4, 20266.527NONO
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
Mar 16, 20238.827NONO
In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM
Oct 14, 20228.126NONO
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
Feb 22, 20237.525NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA68 CVEs
Severity distribution among all CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local5 (7.4%)
Network63 (92.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (91.2%)
High6 (8.8%)
Unknown0 (0.0%)
User Interaction
None55 (80.9%)
Unknown0 (0.0%)
Required12 (17.6%)
Privileges Required
Low26 (38.2%)
High5 (7.4%)
None37 (54.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (68 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Octopus Deploy as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Octopus Deploy as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs