Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Koji Project

First CVE: Oct 6, 2017Active for: 9 yearsTotal CVEs: 3

Koji is a build and release-management system widely used in open-source distribution pipelines, particularly within the Red Hat and Fedora ecosystems, where its role in artifact provenance and integrity makes even modest flaws operationally significant. The observed vulnerability profile centers on input-validation issues, path-traversal weaknesses, and improper permission assignment on critical resources—flaws that reflect the system's responsibility for authenticating build requests, managing filesystem boundaries, and controlling access to build artifacts and metadata. Current severity, exploitation activity, and exposure details are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
More Total CVEs than 72% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Koji Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2017
8 years ago
Most Recent CVE
Oct 9, 2019
2,480 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1002150CRITICAL
Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in v
Apr 4, 20189.128NONO
CVE-2017-1002153HIGH
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
Oct 6, 20177.524NONO
CVE-2019-17109MEDIUM
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
Oct 9, 20196.522NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (33.3%)
High0 (0.0%)
None2 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Koji Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Koji Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Koji Project's Products

View all 2 CNAs →

Top CWEs