Celeryproject maintains Celery, a distributed task-queue library widely embedded in Python-based backend systems, whose narrow product footprint masks broad downstream deployment across web applications and microservices. The observed vulnerability signal centers on command-injection flaws arising from improper handling of special elements in task arguments and execution contexts, a risk inherent to a system that schedules and deserializes workloads across distributed workers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Celeryproject over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23727HIGH This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the da | Dec 29, 2021 | 7.5 | 27 | NO | NO |
CVE-2011-4356MEDIUM Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid and --gid arguments to celerybea | Dec 5, 2011 | 6.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Celeryproject.
Media articles that mention a CVE ID that affects a product developed by Celeryproject — matched by CVE ID, not by vendor name.