Litestream is a specialized replication and backup tool for SQLite databases, with a narrow product scope centered on its core replication software. The observed vulnerability patterns reflect cryptographic and access-control concerns, with recurring weaknesses in authorization mechanisms and signature verification that are characteristic of systems handling authentication and data integrity. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Litestream over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41254MEDIUM An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive informat | Jul 31, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Litestream.
Media articles that mention a CVE ID that affects a product developed by Litestream — matched by CVE ID, not by vendor name.