Blackfire is a performance-monitoring and profiling tool for PHP applications, with its vulnerability footprint centered on authentication controls in its Docker image distribution. The durable signal reflects access-control weaknesses in containerized deployments, a structural concern for defenders managing this tooling in their environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blackfire over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35466CRITICAL The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote at | Dec 15, 2020 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blackfire.
Media articles that mention a CVE ID that affects a product developed by Blackfire — matched by CVE ID, not by vendor name.