Netflix, Inc. operates a portfolio of internal infrastructure and orchestration tools including dispatch, chaos_monkey, lemur, conductor, and consoleme, which address load balancing, secret management, chaos engineering, and access control across its platform. Vulnerabilities affecting these tools skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including expression language injection, authorization bypass, insufficient randomness in cryptographic contexts, and sensitive information disclosure—patterns typical of business-logic and credential-handling components. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netflix, Inc. over time
Of all the CVEs published by Netflix, Inc. as a CNA, 71.4% affect products that Netflix, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Netflix, Inc., 62.5% are self-published by Netflix, Inc. as a CNA.
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27177CRITICAL A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 | Apr 1, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-9297CRITICAL Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messag | Jul 14, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-9296CRITICAL Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are suppo | Jun 16, 2020 | 9.8 | 31 | NO | NO |
CVE-2024-7093CRITICAL Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. | Aug 1, 2024 | 9.4 | 26 | NO | NO |
CVE-2023-30797HIGH Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the creden | Apr 19, 2023 | 7.5 | 25 | NO | NO |
CVE-2019-10028HIGH Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019. | Jun 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2020-2322HIGH Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to ge | Dec 3, 2020 | 7.5 | 24 | NO | NO |
CVE-2023-40171HIGH Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugin | Aug 17, 2023 | 7.5 | 23 | NO | NO |
CVE-2024-9301HIGH A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a | Sep 27, 2024 | 7.5 | 22 | NO | NO |
CVE-2020-9300MEDIUM The Access Control issues include allowing a regular user to view a restricted incident, user role escalation to admin, users adding themselves as a participant in a restricted inc | Nov 9, 2020 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netflix, Inc..
Media articles that mention a CVE ID that affects a product developed by Netflix, Inc. — matched by CVE ID, not by vendor name.