Layer5 maintains Meshery, a management and configuration platform for service mesh deployments, a narrowly scoped but prominent role in cloud-native infrastructure. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the elevated privileges and network access inherent to mesh management tools. The recurring weakness classes—SQL injection and improper access control—center on the platform's data-handling and authorization boundaries, areas where flaws can directly compromise the underlying service mesh and workloads it orchestrates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Layer5 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31856CRITICAL A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the /experimental/patternfiles endpoint (order parame | Apr 28, 2021 | 9.8 | 80 | NO | YES |
CVE-2024-36535CRITICAL Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. | Jul 24, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-35181HIGH Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery | May 27, 2024 | 8.1 | 24 | NO | NO |
CVE-2023-46575CRITICAL A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensitive information and execute arbitrary code through the “orde | Nov 24, 2023 | 9.8 | 24 | NO | NO |
CVE-2024-35182HIGH Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery | May 27, 2024 | 8.1 | 23 | NO | NO |
CVE-2024-29031HIGH Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery | Mar 21, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Layer5.
Media articles that mention a CVE ID that affects a product developed by Layer5 — matched by CVE ID, not by vendor name.