Libfuse is a userspace filesystem abstraction library that remains niche in direct adoption but occupies a critical role in systems where filesystem virtualization is required, with vulnerabilities centering on its single primary product. The recurring weakness classes—link-following conditions, NULL pointer dereferences, and use-after-free flaws—reflect the memory-safety and symlink-handling demands of filesystem interposition logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libfuse Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3879MEDIUM FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent di | Jan 22, 2011 | 5.8 | 34 | NO | YES |
CVE-2026-33150HIGH libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows | Mar 20, 2026 | 7.8 | 30 | NO | NO |
CVE-2026-33179MEDIUM libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows | Mar 20, 2026 | 5.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libfuse Project.
Media articles that mention a CVE ID that affects a product developed by Libfuse Project — matched by CVE ID, not by vendor name.