Palantir Technologies

First CVE: Apr 26, 2022Active for: 4 years
47
CVEs Published
More CVEs Published than 56% of tracked CNAs
9.4
Avg CVEs / Year
More Avg CVEs / Year than 51% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Palantir Technologies as a CNA, 70.2% affect products that Palantir Technologies develops as a vendor.

70.2%
29.8%
Self-reported: 33Third-party: 14

Of all the CVEs published that affect products developed by Palantir Technologies, 100.0% are self-published by Palantir Technologies as a CNA.

100.0%
Self-published: 33Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Palantir Technologies over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 26, 2022
4 years ago
Most Recent CVE
Jan 22, 2026
183 days ago

Top CVEs

All CVEs published by Palantir Technologies as a CNA, regardless of affected vendor or product.

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directl
Dec 19, 20259.130NONO
The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perf
Jun 14, 20229.129NONO
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vuln
Jun 26, 20239.826NONO
Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python c
Nov 14, 20227.525NONO
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypa
Dec 18, 20257.524NONO
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.
Oct 26, 20237.524NONO
Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions e
Nov 15, 20227.524NONO
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly u
Feb 16, 20237.523NONO
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service.
Feb 16, 20237.523NONO
It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privileg
Feb 16, 20237.423NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA47 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (4.3%)
Network44 (93.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.1%)
Attack Complexity
Low37 (78.7%)
High10 (21.3%)
Unknown0 (0.0%)
User Interaction
None36 (76.6%)
Unknown0 (0.0%)
Required11 (23.4%)
Privileges Required
Low27 (57.4%)
High4 (8.5%)
None16 (34.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Palantir Technologies as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Palantir Technologies as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs