Tigera, Inc.

First CVE: Jun 3, 2020Active for: 6 years
7
CVEs Published
More CVEs Published than 20% of tracked CNAs
1.4
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Tigera, Inc. as a CNA, 57.1% affect products that Tigera, Inc. develops as a vendor.

57.1%
42.9%
Self-reported: 4Third-party: 3

Of all the CVEs published that affect products developed by Tigera, Inc., 100.0% are self-published by Tigera, Inc. as a CNA.

100.0%
Self-published: 4Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Tigera, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2020
6 years ago
Most Recent CVE
May 28, 2026
57 days ago

Top CVEs

All CVEs published by Tigera, Inc. as a CNA, regardless of affected vendor or product.

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration struct to stderr in a single log li
May 28, 20267.227NONO
When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin
May 28, 20266.524NONO
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Can
May 28, 20266.524NONO
In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico
Nov 6, 20237.522NONO
In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has local acc
Apr 29, 20246.719NONO
Clusters using Calico (version 3.14.0 and below), Calico Enterprise (version 2.8.2 and below), may be vulnerable to information disclosure if IPv6 is enabled but unused. A compromi
Jun 3, 20203.517NONO
Clusters using Calico (version 3.22.1 and below), Calico Enterprise (version 3.12.0 and below), may be vulnerable to route hijacking with the floating IP feature. Due to insufficie
Jun 6, 20225.516NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA7 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High2 (28.6%)
None1 (14.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Tigera, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Tigera, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs