Cloud Foundry's vulnerability profile centers on an open-source platform-as-a-service framework and its deployment tooling, which serves as critical infrastructure for containerized application management across cloud environments. Although the vendor maintains a focused product portfolio, its prominent role in enterprise cloud deployments and integration with widely used orchestration and release-automation components elevates its operational importance. The recurring exposure patterns reflect the complexity of access control, credential handling, and input validation in a multi-tenant platform context, with weakness classes including improper privilege management, sensitive-information disclosure, and input-validation gaps appearing across deployment and runtime components. Defenders should monitor this vendor's advisories closely and treat patches for the deployment and release automation layers as high-priority given their scope across hosted applications and infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudfoundry over time
Signals from CVEs in this vendor scope (125 CVEs).
125 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-47826CRITICAL The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.
Affected versions: BOSH CLI to | Jul 9, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-47828HIGH During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server c | Jul 9, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-47829HIGH Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh l | Jul 9, 2026 | 7.8 | 35 | NO | NO |
CVE-2026-41857HIGH A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default | Jul 9, 2026 | 7.8 | 35 | NO | NO |
CVE-2016-6655CRITICAL An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was d | Jun 13, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-3801CRITICAL Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated mali | Apr 25, 2019 | 9.8 | 31 | NO | NO |
CVE-2016-0761CRITICAL Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation t | May 25, 2017 | 9.8 | 30 | NO | NO |
CVE-2022-31733CRITICAL Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing applicatio | Feb 3, 2023 | 9.1 | 29 | NO | NO |
CVE-2018-25046CRITICAL Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | Dec 27, 2022 | 9.1 | 29 | NO | NO |
CVE-2018-1195HIGH In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authenticatio | Mar 19, 2018 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (125 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudfoundry.
Media articles that mention a CVE ID that affects a product developed by Cloudfoundry — matched by CVE ID, not by vendor name.