Cloudevents is a specification project with a narrowly scoped Go SDK implementation, positioning it in the cloud-native and event-driven middleware layer rather than as a mainstream application vendor. The observed vulnerability surface centers on credential-handling weaknesses in the SDK, reflecting the authentication and secret-management concerns inherent to distributed event systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudevents over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28110HIGH Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudeven | Mar 6, 2024 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudevents.
Media articles that mention a CVE ID that affects a product developed by Cloudevents — matched by CVE ID, not by vendor name.