Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Keylime

First CVE: Feb 25, 2021Active for: 5 yearsTotal CVEs: 13
45.6
VTI Score
High

Keylime is a specialized attestation and runtime integrity-verification platform that integrates with trusted platform modules (TPMs) to validate system trustworthiness, occupying a focused but strategically important role in cloud and infrastructure security. Its vulnerability profile skews toward serious outcomes, with a substantial share of disclosures reaching critical severity, and the recurring weaknesses center on authentication bypass, authorization flaws, and information exposure—issues that directly undermine the integrity guarantees the platform is designed to enforce. Defenders relying on Keylime for attestation in sensitive infrastructure should prioritize tracking and deploying its updates; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Keylime over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 25, 2021
5 years ago
Most Recent CVE
Feb 6, 2026
168 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-1709CRITICAL
A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vul
Feb 6, 20269.839NONO
CVE-2021-43310CRITICAL
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This coul
Sep 21, 20229.831NONO
CVE-2021-3406CRITICAL
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to
Feb 25, 20219.831NONO
CVE-2022-23949HIGH
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.
Sep 21, 20227.525NONO
CVE-2022-23952HIGH
In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as world-readable.
Sep 21, 20227.524NONO
CVE-2022-23950HIGH
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
Sep 21, 20227.524NONO
CVE-2022-23948HIGH
A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivileged mounts allowing secrets to
Sep 21, 20227.524NONO
CVE-2022-1053CRITICAL
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity
May 6, 20229.124NONO
CVE-2023-38200HIGH
A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker
Jul 24, 20237.522NONO
CVE-2023-38201MEDIUM
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an
Aug 25, 20236.520NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
23%
38%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (23.1%)
Network9 (69.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (7.7%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None12 (92.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Keylime.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Keylime — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Keylime's Products

View all 2 CNAs →

Top CWEs