Defense Unicorns maintains Pepr, a policy-as-code framework for Kubernetes environments, with observed vulnerabilities clustering around authentication mechanisms and privilege-boundary enforcement. The durable exposure pattern reflects the framework's role in access control and configuration validation within container orchestration platforms; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Defenseunicorns over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46389CRITICAL UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, | Jun 5, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-23634MEDIUM Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for modul | Jan 16, 2026 | 4.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Defenseunicorns.
Media articles that mention a CVE ID that affects a product developed by Defenseunicorns — matched by CVE ID, not by vendor name.