The Kerberos Project maintains a foundational network authentication protocol and reference implementation that is widely embedded in enterprise infrastructure and operating systems, despite its narrow direct product footprint. The durable signal from its vulnerability disclosures centers on path-handling and library-loading mechanisms, reflected in recurrent weaknesses such as uncontrolled search path elements that can arise in authentication library implementations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kerberos Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13110HIGH The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary( | May 16, 2020 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kerberos Project.
Media articles that mention a CVE ID that affects a product developed by Kerberos Project — matched by CVE ID, not by vendor name.