Galaxy is a widely used open-source genomics and bioinformatics analysis platform that provides web-based data processing and workflow execution, concentrating its vulnerability exposure in this single core product. Vulnerabilities affecting the platform skew strongly toward critical severity and recur across web-application input handling, authentication, and data-access control—chiefly cross-site scripting, sensitive information disclosure, path traversal, injection flaws, and improper access control—reflecting the complexity of exposing computational pipelines and genomic datasets through a web interface. Defenders should prioritize patching this platform where it accesses sensitive research or clinical data; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Galaxyproject over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-10062CRITICAL A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14.10.0. This affects an unknown part of the component Command Line Template. The mani | Jan 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-42351CRITICAL Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potential | Sep 20, 2024 | 9.1 | 28 | NO | NO |
CVE-2023-27578HIGH Galaxy is an open-source platform for data analysis. All supported versions of Galaxy are affected prior to 22.01, 22.05, and 23.0 are affected by an insufficient permission check. | Mar 20, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-23470HIGH Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any fil | Dec 6, 2022 | 7.5 | 19 | NO | NO |
CVE-2018-1000516MEDIUM The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server di | Jun 26, 2018 | 6.1 | 19 | NO | NO |
CVE-2024-42346MEDIUM Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, | Sep 20, 2024 | 5.4 | 18 | NO | NO |
CVE-2023-42812MEDIUM Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary H | Sep 22, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Galaxyproject.
Media articles that mention a CVE ID that affects a product developed by Galaxyproject — matched by CVE ID, not by vendor name.