Pulsar

Vendor:

First CVE: May 26, 2021 · Active for 5 years

20
Total CVEs
More Total CVEs than 94% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pulsar over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2021
5 years ago
Most Recent CVE
Apr 9, 2025
471 days ago

CVE Severity & Scoring

Pulsar20 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (75.0%)
High5 (25.0%)
Unknown0 (0.0%)
User Interaction
None20 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low12 (60.0%)
High0 (0.0%)
None8 (40.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented to
May 26, 20219.861NONO
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a m
Mar 12, 20249.960NONO
Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes
Mar 12, 20249.932NONO
The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Credential Flow, even when tlsAllowInsecureConnection is disabled
Nov 4, 20228.127NONO
The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL
Mar 12, 20248.826NONO
Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Puls
Jul 12, 20238.826NONO
Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes deta
Mar 12, 20248.224NONO
This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering
Apr 2, 20246.422NONO
Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Us
Feb 7, 20247.422NONO
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pu
Dec 20, 20237.522NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Pulsar

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.048.516.6%00
3.1.027.71.1%00
3.0.017.51.4%00
2.8.016.51.7%00
2.11.047.50.9%00
2.10.035.90.6%00