Octopus Deploy
First CVE: Jun 17, 2021Active for: 5 years
68
CVEs Published
More CVEs Published than 65% of tracked CNAs
11.3
Avg CVEs / Year
More Avg CVEs / Year than 57% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Octopus Deploy as a CNA, 98.5% affect products that Octopus Deploy develops as a vendor.
98.5%
Self-reported: 67Third-party: 1
Of all the CVEs published that affect products developed by Octopus Deploy, 64.4% are self-published by Octopus Deploy as a CNA.
64.4%
35.6%
Self-published: 67Published by other CNAs: 37
Trends Over Time
The number and severity of CVEs published by Octopus Deploy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2021
5 years ago
Most Recent CVE
Jul 24, 2026
2 days ago
Top CVEs
All CVEs published by Octopus Deploy as a CNA, regardless of affected vendor or product.
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2572CRITICAL In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still v | Nov 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-2778CRITICAL In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | Sep 30, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-31819CRITICAL In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate ver | Sep 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-0704CRITICAL In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentiall | Feb 25, 2026 | 9.1 | 29 | NO | NO |
CVE-2024-9194CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Inject | Sep 30, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-2782CRITICAL In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters. | Oct 27, 2022 | 9.1 | 28 | NO | NO |
CVE-2026-4881MEDIUM In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpo | Jun 4, 2026 | 6.5 | 27 | NO | NO |
CVE-2022-4009HIGH In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation | Mar 16, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-2780HIGH In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM | Oct 14, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-2883HIGH In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | Feb 22, 2023 | 7.5 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA68 CVEs
56%
29%
9%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (7.4%)
Network63 (92.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (91.2%)
High6 (8.8%)
Unknown0 (0.0%)
User Interaction
None55 (80.9%)
Unknown0 (0.0%)
Required12 (17.6%)
Privileges Required
Low26 (38.2%)
High5 (7.4%)
None37 (54.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (68 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Octopus Deploy as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Octopus Deploy as a CNA — matched by CVE ID, not by organization name.