Keepalived is a widely deployed high-availability and load-balancing daemon used across Linux infrastructure to manage virtual IP failover and service redundancy, representing a critical control point in many production networks despite its narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while the recurring weakness classes including sensitive-information exposure, improper link resolution, and out-of-bounds writes reflect the daemon's privileged role in network configuration and memory-handling demands. Defenders should prioritize patches for this vendor given its exposure in failover-critical systems; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keepalived over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19115CRITICAL keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/ht | Nov 8, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-19045HIGH keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information. | Nov 8, 2018 | 7.5 | 25 | NO | NO |
CVE-2021-44225MEDIUM In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access | Nov 26, 2021 | 5.4 | 21 | NO | NO |
CVE-2018-19044MEDIUM keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitr | Nov 8, 2018 | 4.7 | 19 | NO | NO |
CVE-2018-19046MEDIUM keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a fi | Nov 8, 2018 | 4.7 | 18 | NO | NO |
The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, and (3) vrrp.pid files in /var/run/ | May 20, 2011 | 3.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keepalived.
Media articles that mention a CVE ID that affects a product developed by Keepalived — matched by CVE ID, not by vendor name.