Tigera, Inc.
First CVE: Jun 3, 2020Active for: 6 years
7
CVEs Published
More CVEs Published than 20% of tracked CNAs
1.4
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Tigera, Inc. as a CNA, 57.1% affect products that Tigera, Inc. develops as a vendor.
57.1%
42.9%
Self-reported: 4Third-party: 3
Of all the CVEs published that affect products developed by Tigera, Inc., 100.0% are self-published by Tigera, Inc. as a CNA.
100.0%
Self-published: 4Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by Tigera, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2020
6 years ago
Most Recent CVE
May 28, 2026
57 days ago
Top CVEs
All CVEs published by Tigera, Inc. as a CNA, regardless of affected vendor or product.
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6720HIGH When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log li | May 28, 2026 | 7.2 | 27 | NO | NO |
CVE-2026-41185MEDIUM When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin | May 28, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-41184MEDIUM In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Can | May 28, 2026 | 6.5 | 24 | NO | NO |
CVE-2023-41378HIGH In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico | Nov 6, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-33522MEDIUM In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local acc | Apr 29, 2024 | 6.7 | 19 | NO | NO |
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromi | Jun 3, 2020 | 3.5 | 17 | NO | NO |
CVE-2022-28224MEDIUM Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficie | Jun 6, 2022 | 5.5 | 16 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA7 CVEs
14%
57%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High2 (28.6%)
None1 (14.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Tigera, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Tigera, Inc. as a CNA — matched by CVE ID, not by organization name.