Apt Cacher Ng Project maintains a package-caching proxy for Debian and Ubuntu systems that, despite narrow scope, occupies a trusted position in Linux infrastructure where it mediates repository access and software distribution. The durable exposure centers on the single apt-cacher-ng product and its role as a network intermediary for package management. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apt Cacher Ng Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11147MEDIUM Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”. | Sep 29, 2025 | 5.4 | 21 | NO | NO |
CVE-2017-7443MEDIUM apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression. | Apr 5, 2017 | 6.1 | 21 | NO | NO |
CVE-2025-11146MEDIUM Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnera | Sep 29, 2025 | 5.4 | 20 | NO | NO |
CVE-2019-18899MEDIUM The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the out | Jan 23, 2020 | 5.5 | 20 | NO | NO |
CVE-2020-5202MEDIUM apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to | Jan 21, 2020 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apt Cacher Ng Project.
Media articles that mention a CVE ID that affects a product developed by Apt Cacher Ng Project — matched by CVE ID, not by vendor name.