Dependabot is a dependency-management and automated-update tool that integrates with version-control platforms to identify and patch vulnerable libraries and dependencies. Its observed vulnerability surface centers on injection-class weaknesses in the tool's handling of downstream package metadata and output, reflecting the inherent complexity of parsing and neutralizing untrusted dependency data. Current CVE counts, severity breakdowns, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dependabot Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26222HIGH Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Dependabot-Core from version 0.119.0 | Nov 13, 2020 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dependabot Project.
Media articles that mention a CVE ID that affects a product developed by Dependabot Project — matched by CVE ID, not by vendor name.