Buildbot is a continuous-integration automation platform whose vulnerability exposure centers on web-interface attack vectors, with the recurring weakness classes spanning cross-site scripting, authentication bypass, and CRLF injection—issues typical of application-layer input handling in systems exposed to untrusted build environments. The vendor's footprint is narrow and specialized, making it a targeted concern primarily for organizations operating self-hosted CI/CD infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buildbot over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12300CRITICAL Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to r | May 23, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-7313MEDIUM www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in th | Feb 3, 2019 | 6.1 | 20 | NO | NO |
CVE-2009-2967MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, differ | Aug 26, 2009 | 4.3 | 17 | NO | NO |
CVE-2009-2959MEDIUM Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary w | Aug 25, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buildbot.
Media articles that mention a CVE ID that affects a product developed by Buildbot — matched by CVE ID, not by vendor name.