Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Anaconda

First CVE: Oct 26, 2021Active for: 5 yearsTotal CVEs: 10
40.6
VTI Score
High

Anaconda maintains a narrowly scoped portfolio centered on its Python distribution and package management ecosystem, including Anaconda3, conda-build, and data-processing tools such as Dask that hold prominent positions in scientific computing and machine-learning development environments. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and recurs through privilege-escalation and code-injection risks—including incorrect permission assignment, execution with unnecessary privileges, certificate validation flaws, and path-traversal weaknesses—that reflect the trust relationship between package managers and their users and the elevated permissions required by build and runtime tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Anaconda over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 26, 2021
4 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-42343CRITICAL
An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Cli
Oct 26, 20219.831NONO
CVE-2025-32800CRITICAL
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published
Jun 16, 20259.830NONO
CVE-2025-32799CRITICAL
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to
Jun 16, 20259.828NONO
CVE-2025-32798CRITICAL
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code
Jun 16, 20259.827NONO
CVE-2021-42969HIGH
Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the u
May 13, 20228.826NONO
CVE-2024-46060HIGH
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable
Dec 17, 20257.825NONO
CVE-2022-26526HIGH
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory in
Mar 17, 20227.825NONO
CVE-2026-23528MEDIUM
Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to c
Jan 16, 20266.122NONO
CVE-2025-32797HIGH
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_b
Jun 16, 20257.021NONO
CVE-2023-35845MEDIUM
Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many fil
Sep 11, 20234.718NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
20%
40%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (40.0%)
Network6 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low4 (40.0%)
High0 (0.0%)
None6 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Anaconda.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Anaconda — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Anaconda's Products

View all 2 CNAs →

Top CWEs