Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Alpine Project

First CVE: Jun 19, 2020Active for: 6 yearsTotal CVEs: 5

Alpine Project maintains a lightweight Linux distribution optimized for containerized and embedded environments, with a focused vulnerability profile centered on its core Alpine Linux product. Observed weaknesses cluster around authentication mechanisms, command-injection resistance, and authorization boundaries, reflecting the attack surface of a minimal operating system widely deployed in container images and edge devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Alpine Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2020
6 years ago
Most Recent CVE
Dec 28, 2022
1,304 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-23553HIGH
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds
Dec 28, 20227.525NONO
CVE-2021-46853MEDIUM
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
Nov 3, 20225.922NONO
CVE-2020-14929HIGH
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alterna
Jun 19, 20207.522NONO
CVE-2022-23554MEDIUM
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the u
Dec 28, 20225.421NONO
CVE-2021-38370MEDIUM
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
Aug 10, 20215.921NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
60%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High2 (40.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Alpine Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Alpine Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Alpine Project's Products

View all 2 CNAs →

Top CWEs