Palantir Technologies
Self-Reporting Analysis
Of all the CVEs published by Palantir Technologies as a CNA, 70.2% affect products that Palantir Technologies develops as a vendor.
Of all the CVEs published that affect products developed by Palantir Technologies, 100.0% are self-published by Palantir Technologies as a CNA.
Trends Over Time
The number and severity of CVEs published by Palantir Technologies over time
Top CVEs
All CVEs published by Palantir Technologies as a CNA, regardless of affected vendor or product.
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-49587CRITICAL Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directl | Dec 19, 2025 | 9.1 | 30 | NO | NO |
CVE-2022-27889CRITICAL The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perf | Jun 14, 2022 | 9.1 | 29 | NO | NO |
CVE-2023-30945CRITICAL Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vuln | Jun 26, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-27896HIGH Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python c | Nov 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2025-53710HIGH Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypa | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-30967HIGH Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. | Oct 26, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-27895HIGH Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions e | Nov 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-27897HIGH Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly u | Feb 16, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-27892HIGH Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service. | Feb 16, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-27890HIGH It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privileg | Feb 16, 2023 | 7.4 | 23 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (47 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Palantir Technologies as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Palantir Technologies as a CNA — matched by CVE ID, not by organization name.