Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Alpinelinux

First CVE: Jul 17, 2017Active for: 9 yearsTotal CVEs: 6

Alpine Linux is a lightweight, container-oriented Linux distribution whose compact vulnerability footprint belies its prominence in containerized and embedded deployments, where minimalism and supply-chain simplicity are prized. Vulnerabilities affecting the distribution skew toward serious outcomes and concentrate in core packaging and build infrastructure—Alpine Linux itself, the APK package manager and tooling, and the Aports repository—with recurring weaknesses in memory-safety, credential handling, and input validation that reflect the boundaries of a minimal userland and its integration points. Defenders relying on Alpine for container images and lightweight deployments should treat security updates for the base system and package tooling as high-priority given the distribution's role in the build and runtime supply chain; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Alpinelinux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
Jul 5, 2021
1,849 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1000849HIGH
Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code
Dec 20, 20188.827NONO
CVE-2017-9671HIGH
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz fi
Jul 17, 20177.826NONO
CVE-2017-9669HIGH
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz fil
Jul 17, 20177.826NONO
CVE-2021-30139HIGH
In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.
Apr 21, 20217.523NONO
CVE-2019-12875MEDIUM
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signi
Jun 18, 20196.522NONO
CVE-2021-36158MEDIUM
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys ar
Jul 5, 20215.921NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
67%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (33.3%)
Network4 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Alpinelinux.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Alpinelinux — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Alpinelinux's Products

View all 1 CNAs →

Top CWEs