Augeas is a configuration-file parsing and manipulation library deployed across Linux systems and management tooling, presenting a modest but strategically important attack surface where parsing errors can affect system configuration integrity. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and center on memory-safety and file-handling weakness classes including heap-based buffer overflows, path-traversal conditions, link-following flaws, and improper resource cleanup that are characteristic of C-based parsers operating on untrusted configuration data. Defenders should track this vendor's updates because flaws in configuration parsing can propagate through downstream automation and management platforms; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Augeas over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7555CRITICAL Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would c | Aug 17, 2017 | 9.8 | 33 | NO | NO |
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrit | Nov 23, 2013 | 3.7 | 16 | NO | NO |
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulatio | Mar 21, 2025 | 3.3 | 15 | NO | NO |
The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsav | Nov 23, 2013 | 3.3 | 15 | NO | NO |
The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew | Nov 23, 2013 | 3.3 | 15 | NO | NO |
CVE-2013-6412MEDIUM The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writabl | Jan 23, 2014 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Augeas.
Media articles that mention a CVE ID that affects a product developed by Augeas — matched by CVE ID, not by vendor name.