Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fluxcd

First CVE: Nov 12, 2021Active for: 5 yearsTotal CVEs: 7

Flux CD is a continuous-delivery platform for Kubernetes that automates application deployment and configuration management through declarative, Git-driven workflows. Its vulnerability profile, concentrated in components such as Flux2, Kustomize Controller, and Helm Controller, skews toward serious outcomes with an elevated share reaching critical severity, driven by recurrent weakness classes including path traversal, code injection, and OS command injection that arise in the parsing and execution of manifests and configurations. Defenders should treat Flux CD advisories as high-priority in environments where the platform reconciles untrusted or externally sourced Kubernetes configurations; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fluxcd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2021
4 years ago
Most Recent CVE
Oct 22, 2022
1,371 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24817CRITICAL
Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1
May 6, 20229.931NONO
CVE-2022-24877HIGH
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to ex
May 6, 20228.828NONO
CVE-2021-41254HIGH
kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled
Nov 12, 20218.828NONO
CVE-2022-36035HIGH
Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to depl
Aug 31, 20227.825NONO
CVE-2022-24878MEDIUM
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to ca
May 6, 20226.523NONO
CVE-2022-39272MEDIUM
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’
Oct 22, 20224.319NONO
CVE-2022-36049HIGH
Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage H
Sep 7, 20227.519NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
29%
57%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (85.7%)
High0 (0.0%)
None1 (14.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fluxcd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fluxcd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fluxcd's Products

View all 1 CNAs →

Top CWEs