Gssproxy is a niche GSSAPI proxy service that mediates authentication and credential handling for networked systems, presenting a focused and specialized attack surface within enterprise Kerberos and GSSAPI infrastructures. Its observed vulnerability surface centers on the gssproxy daemon itself and recurs through concurrency-related weakness classes such as improper locking, reflecting the inherent challenges of managing shared authentication state across multiple client connections.
The number and severity of CVEs published that impact products developed by Gssproxy Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12658CRITICAL gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shut | Dec 31, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gssproxy Project.
Media articles that mention a CVE ID that affects a product developed by Gssproxy Project — matched by CVE ID, not by vendor name.