Cygwin provides a POSIX compatibility layer and collection of Unix-like tools for Windows, with exposure centered on its core environment and bundled utilities such as Git. The durable signal from its disclosures reflects the complexity of translating between Windows and POSIX semantics, with recurring weaknesses in input validation and memory-boundary handling characteristic of systems-level compatibility work. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cygwin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3067CRITICAL Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges. | Apr 21, 2017 | 9.8 | 31 | NO | NO |
CVE-2021-29468HIGH Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that contains symbolic links as well as files with backslash char | Apr 29, 2021 | 8.8 | 27 | NO | NO |
CVE-2017-7523HIGH Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the proc | Jul 21, 2017 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cygwin.
Media articles that mention a CVE ID that affects a product developed by Cygwin — matched by CVE ID, not by vendor name.