Finos maintains a focused portfolio of financial-services infrastructure tooling, with its tracked vulnerability exposure concentrating in the GitProxy product and centered on authorization and data-handling weaknesses. The recurring pattern involves improper or incorrect authorization checks and exposure of sensitive information to unauthorized actors, reflecting the access-control and credential-management demands of a credential-proxy component operating in regulated environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Finos over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54586MEDIUM GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the pack sent to GitHub | Jul 30, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-54585MEDIUM GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitProxy handles new branch creatio | Jul 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-54583MEDIUM GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while b | Jul 30, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-54584MEDIUM GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a malicious Git packfile | Jul 30, 2025 | 5.7 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Finos.
Media articles that mention a CVE ID that affects a product developed by Finos — matched by CVE ID, not by vendor name.