Pulsar
Vendor:
First CVE: May 26, 2021 · Active for 5 years
20
Total CVEs
More Total CVEs than 94% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pulsar over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2021
5 years ago
Most Recent CVE
Apr 9, 2025
471 days ago
CVE Severity & Scoring
Pulsar20 CVEs
50%
35%
15%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (75.0%)
High5 (25.0%)
Unknown0 (0.0%)
User Interaction
None20 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low12 (60.0%)
High0 (0.0%)
None8 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22160CRITICAL If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented to | May 26, 2021 | 9.8 | 61 | NO | NO |
CVE-2024-27317CRITICAL In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a m | Mar 12, 2024 | 9.9 | 60 | NO | NO |
CVE-2024-27135CRITICAL Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes | Mar 12, 2024 | 9.9 | 32 | NO | NO |
CVE-2022-33684HIGH The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled | Nov 4, 2022 | 8.1 | 27 | NO | NO |
CVE-2024-27894HIGH The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL | Mar 12, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-30429HIGH Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar.
This issue affects Apache Pulsar: before 2.10.4, and 2.11.0.
When a client connects to the Puls | Jul 12, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-34321HIGH Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes deta | Mar 12, 2024 | 8.2 | 24 | NO | NO |
CVE-2024-29834MEDIUM This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering | Apr 2, 2024 | 6.4 | 22 | NO | NO |
CVE-2023-51437HIGH Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification.
Us | Feb 7, 2024 | 7.4 | 22 | NO | NO |
CVE-2023-37544HIGH Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication.
This issue affects Apache Pu | Dec 20, 2023 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Pulsar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.0 | 4 | 8.5 | 16.6% | 0 | 0 |
| 3.1.0 | 2 | 7.7 | 1.1% | 0 | 0 |
| 3.0.0 | 1 | 7.5 | 1.4% | 0 | 0 |
| 2.8.0 | 1 | 6.5 | 1.7% | 0 | 0 |
| 2.11.0 | 4 | 7.5 | 0.9% | 0 | 0 |
| 2.10.0 | 3 | 5.9 | 0.6% | 0 | 0 |