Linkerd is a service mesh platform that operates as a lightweight proxy layer for Kubernetes clusters, with a focused product footprint centered on the core Linkerd proxy and associated Buoyant offerings. The durable signal from its disclosure history points to resource-consumption and information-handling issues, which reflect the networking and orchestration demands of service mesh data planes that process high volumes of traffic and manage stateful connections. Current CVE counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linkerd over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2025-43915MEDIUM In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4, and 2.17.0–2.17.1, resource ex | May 5, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linkerd.
Media articles that mention a CVE ID that affects a product developed by Linkerd — matched by CVE ID, not by vendor name.