Bpg develops a Terraform provider component that operates within the infrastructure-as-code ecosystem and presents a narrowly scoped attack surface. The durable signal centers on path-traversal and insecure-default vulnerabilities, which are characteristic of configuration-management and provisioning tools that handle file paths and resource initialization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bpg over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25499HIGH Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configuration documentation, the sudoer line suggested is insecure a | Feb 4, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bpg.
Media articles that mention a CVE ID that affects a product developed by Bpg — matched by CVE ID, not by vendor name.