Alpine Project maintains a lightweight Linux distribution optimized for containerized and embedded environments, with a focused vulnerability profile centered on its core Alpine Linux product. Observed weaknesses cluster around authentication mechanisms, command-injection resistance, and authorization boundaries, reflecting the attack surface of a minimal operating system widely deployed in container images and edge devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alpine Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23553HIGH Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds | Dec 28, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-46853MEDIUM Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. | Nov 3, 2022 | 5.9 | 22 | NO | NO |
CVE-2020-14929HIGH Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alterna | Jun 19, 2020 | 7.5 | 22 | NO | NO |
CVE-2022-23554MEDIUM Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the u | Dec 28, 2022 | 5.4 | 21 | NO | NO |
CVE-2021-38370MEDIUM In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. | Aug 10, 2021 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alpine Project.
Media articles that mention a CVE ID that affects a product developed by Alpine Project — matched by CVE ID, not by vendor name.