Keylime is a specialized attestation and runtime integrity-verification platform that integrates with trusted platform modules (TPMs) to validate system trustworthiness, occupying a focused but strategically important role in cloud and infrastructure security. Its vulnerability profile skews toward serious outcomes, with a substantial share of disclosures reaching critical severity, and the recurring weaknesses center on authentication bypass, authorization flaws, and information exposure—issues that directly undermine the integrity guarantees the platform is designed to enforce. Defenders relying on Keylime for attestation in sensitive infrastructure should prioritize tracking and deploying its updates; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keylime over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1709CRITICAL A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vul | Feb 6, 2026 | 9.8 | 39 | NO | NO |
CVE-2021-43310CRITICAL A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This coul | Sep 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-3406CRITICAL A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to | Feb 25, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-23949HIGH In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar. | Sep 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-23952HIGH In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable. | Sep 21, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-23950HIGH In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations. | Sep 21, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-23948HIGH A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivileged mounts allowing secrets to | Sep 21, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-1053CRITICAL Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity | May 6, 2022 | 9.1 | 24 | NO | NO |
CVE-2023-38200HIGH A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker | Jul 24, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-38201MEDIUM A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an | Aug 25, 2023 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keylime.
Media articles that mention a CVE ID that affects a product developed by Keylime — matched by CVE ID, not by vendor name.