The Linux Foundation's vulnerability footprint spans a diverse portfolio of foundational and emerging open-source projects, including embedded systems frameworks (Yocto), machine-learning libraries (PyTorch), cryptographic initiatives (Everest), cloud-native infrastructure (NATS Server, Harbor), and other widely adopted tools, representing a significant presence in the software supply chain. Vulnerabilities affecting the vendor's projects skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and access-control demands of systems and infrastructure-layer software. The exposure recurs across these varied products through weakness classes including out-of-bounds reads and writes, path-traversal conditions, and authorization flaws, patterns characteristic of C and systems-code components that handle untrusted input or manage access to system resources. Defenders should monitor this vendor's project advisories broadly, as critical fixes often require coordinated patching across dependent systems; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linuxfoundation over time
Signals from CVEs in this vendor scope (551 CVEs).
551 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2026-45321CRITICAL On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated | May 12, 2026 | 9.6 | 79 | YES | NO |
CVE-2023-27584CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. | Sep 19, 2024 | 9.8 | 61 | NO | YES |
CVE-2024-21626HIGH runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker | Jan 31, 2024 | 8.6 | 54 | NO | YES |
CVE-2021-23450CRITICAL All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. | Dec 17, 2021 | 9.8 | 51 | NO | NO |
CVE-2022-46770HIGH qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafte | Dec 7, 2022 | 7.5 | 47 | NO | YES |
CVE-2019-16097MEDIUM core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend a | Sep 8, 2019 | 6.5 | 46 | NO | YES |
CVE-2026-50195CRITICAL containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the | Jul 1, 2026 | 9.9 | 44 | NO | NO |
CVE-2026-53492CRITICAL containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations f | Jul 1, 2026 | 9.6 | 42 | NO | NO |
CVE-2026-53488HIGH containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instructio | Jul 1, 2026 | 8.8 | 41 | NO | NO |
Signals from CVEs in this vendor scope (551 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxfoundation.
Media articles that mention a CVE ID that affects a product developed by Linuxfoundation — matched by CVE ID, not by vendor name.