Osc maintains Open OnDemand, a web-based platform for high-performance computing cluster access and job management that operates in educational and research environments. The vendor's vulnerability profile centers on web-application and credential-handling issues, including cross-site request forgery, injection flaws, and improper protection of authentication credentials in transport. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osc over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-26002CRITICAL Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when naviga | Mar 4, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-66029HIGH Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malici | Dec 17, 2025 | 7.6 | 25 | NO | NO |
CVE-2020-36247HIGH Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF. | Feb 19, 2021 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osc.
Media articles that mention a CVE ID that affects a product developed by Osc — matched by CVE ID, not by vendor name.