Backblaze develops cloud storage and backup services whose vulnerability profile centers on its B2 platform and command-line tooling, with observed weaknesses recurring around race conditions, certificate validation, and privilege management in API and authentication contexts. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Backblaze over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8289HIGH Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of str | Dec 27, 2020 | 7.8 | 27 | NO | NO |
CVE-2020-8290HIGH Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation be | Dec 27, 2020 | 7.8 | 20 | NO | NO |
CVE-2022-23653MEDIUM B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a | Feb 23, 2022 | 4.7 | 19 | NO | NO |
CVE-2022-23651MEDIUM b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability t | Feb 23, 2022 | 4.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Backblaze.
Media articles that mention a CVE ID that affects a product developed by Backblaze — matched by CVE ID, not by vendor name.