Europa maintains a small portfolio of digital identity and certification infrastructure products, including the eIDAS Node integration package and related technical specifications, primarily supporting European trust and digital credential frameworks. The observed vulnerability surface concentrates on certificate validation gaps, resource-exhaustion conditions, and authorization logic, reflecting the authentication and trust boundaries inherent to identity infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Europa over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40855CRITICAL The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-production public key certificate could have been used in producti | Jan 21, 2022 | 9.8 | 29 | NO | NO |
CVE-2019-18633CRITICAL European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: on | Oct 30, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-18632CRITICAL European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate. | Oct 30, 2019 | 9.8 | 28 | NO | NO |
CVE-2025-3475MEDIUM Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoofing.This issue affects WEB-T: | Apr 9, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Europa.
Media articles that mention a CVE ID that affects a product developed by Europa — matched by CVE ID, not by vendor name.