Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netflix, Inc.

First CVE: Mar 26, 2017Active for: 9 yearsTotal CVEs: 16
28.2
VTI Score
Low

Netflix, Inc. operates a portfolio of internal infrastructure and orchestration tools including dispatch, chaos_monkey, lemur, conductor, and consoleme, which address load balancing, secret management, chaos engineering, and access control across its platform. Vulnerabilities affecting these tools skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including expression language injection, authorization bypass, insufficient randomness in cryptographic contexts, and sensitive information disclosure—patterns typical of business-logic and credential-handling components. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netflix, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2017
9 years ago
Most Recent CVE
Sep 27, 2024
665 days ago

Self-Reporting Analysis

Of all the CVEs published by Netflix, Inc. as a CNA, 71.4% affect products that Netflix, Inc. develops as a vendor.

71.4%
28.6%
Self-reported: 10 (71.4%)
Third-party: 4 (28.6%)

Of all the CVEs published that affect products developed by Netflix, Inc., 62.5% are self-published by Netflix, Inc. as a CNA.

62.5%
37.5%
Self-published: 10 (62.5%)
Other CNAs: 6 (37.5%)

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-27177CRITICAL
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2
Apr 1, 20229.832NONO
CVE-2020-9297CRITICAL
Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messag
Jul 14, 20209.831NONO
CVE-2020-9296CRITICAL
Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are suppo
Jun 16, 20209.831NONO
CVE-2024-7093CRITICAL
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed.
Aug 1, 20249.426NONO
CVE-2023-30797HIGH
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the creden
Apr 19, 20237.525NONO
CVE-2019-10028HIGH
Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.
Jun 21, 20197.525NONO
CVE-2020-2322HIGH
Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to ge
Dec 3, 20207.524NONO
CVE-2023-40171HIGH
Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin
Aug 17, 20237.523NONO
CVE-2024-9301HIGH
A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a
Sep 27, 20247.522NONO
CVE-2020-9300MEDIUM
The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted inc
Nov 9, 20206.522NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
38%
38%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (12.5%)
Network14 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (87.5%)
Unknown0 (0.0%)
Required2 (12.5%)
Privileges Required
Low4 (25.0%)
High1 (6.3%)
None11 (68.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netflix, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netflix, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netflix, Inc.'s Products

View all 5 CNAs →

Top CWEs