Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Apt Cacher Ng Project

First CVE: —Active for: N/ATotal CVEs: 5

Apt Cacher Ng Project maintains a package-caching proxy for Debian and Ubuntu systems that, despite narrow scope, occupies a trusted position in Linux infrastructure where it mediates repository access and software distribution. The durable exposure centers on the single apt-cacher-ng product and its role as a network intermediary for package management. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 78% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Apt Cacher Ng Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2017
9 years ago
Most Recent CVE
Sep 29, 2025
302 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-11147MEDIUM
Reflected cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows malicious scripts (XSS) to be executed in “/html/<filename>.html”.
Sep 29, 20255.421NONO
CVE-2017-7443MEDIUM
apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.
Apr 5, 20176.121NONO
CVE-2025-11146MEDIUM
Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnera
Sep 29, 20255.420NONO
CVE-2019-18899MEDIUM
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the out
Jan 23, 20205.520NONO
CVE-2020-5202MEDIUM
apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to
Jan 21, 20205.519NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
100%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
Medium
Attack Vector
Local2 (40.0%)
Network3 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low4 (80.0%)
High0 (0.0%)
None1 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Apt Cacher Ng Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Apt Cacher Ng Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Apt Cacher Ng Project's Products

View all 3 CNAs →

Top CWEs