Express Gateway is a lightweight, open-source API gateway and microservices platform primarily distributed through containerized deployment, with its observed vulnerability footprint centered on the Docker image artifact. The vendor's disclosures reflect a narrow, focused product scope rather than a broad ecosystem, presenting a compact profile for defenders tracking container-based API infrastructure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Express Gateway over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29579CRITICAL The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions | Dec 8, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Express Gateway.
Media articles that mention a CVE ID that affects a product developed by Express Gateway — matched by CVE ID, not by vendor name.