Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Flatpak

First CVE: Jun 21, 2017Active for: 9 yearsTotal CVEs: 18
39.5
VTI Score
Medium

Flatpak is a containerization framework for distributing Linux applications that has gained prominence in the desktop and server application-delivery landscape. Vulnerabilities affecting the vendor and its associated tools—including the core Flatpak runtime, Flatpak Builder, and the XDG Desktop Portal and D-Bus proxy components—skew toward serious outcomes and recur through a consistent pattern of input-validation, path-traversal, and injection-class flaws that reflect the sandbox-enforcement and inter-process communication layers these tools occupy. Defenders deploying Flatpak in security-sensitive contexts should prioritize advisories around sandboxing bypass and privilege-escalation vectors; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Flatpak over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2017
9 years ago
Most Recent CVE
Apr 11, 2026
104 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-34078CRITICAL
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled sy
Apr 7, 202610.039NONO
CVE-2024-42472CRITICAL
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories coul
Aug 15, 202410.031NONO
CVE-2021-43860HIGH
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the u
Jan 12, 20228.628NONO
CVE-2019-10063CRITICAL
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to
Mar 26, 20199.028NONO
CVE-2024-32462HIGH
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromis
Apr 18, 20248.427NONO
CVE-2018-6560HIGH
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because white
Feb 2, 20188.827NONO
CVE-2026-34079HIGH
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app con
Apr 7, 20267.526NONO
CVE-2021-21261HIGH
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed a
Jan 14, 20218.826NONO
CVE-2017-9780HIGH
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The file
Jun 21, 20177.825NONO
CVE-2022-21682MEDIUM
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies
Jan 13, 20226.524NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
33%
50%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local12 (66.7%)
Network6 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (88.9%)
High2 (11.1%)
Unknown0 (0.0%)
User Interaction
None14 (77.8%)
Unknown0 (0.0%)
Required4 (22.2%)
Privileges Required
Low11 (61.1%)
High0 (0.0%)
None7 (38.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Flatpak.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Flatpak — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Flatpak's Products

View all 2 CNAs →

Top CWEs