Palantir Technologies maintains a focused portfolio of data-integration and analytics platforms, most prominently Foundry and Gotham, that serve intelligence, law-enforcement, and enterprise clients and sit deep within mission-critical operational workflows. Its vulnerability disclosures cluster around a moderate share reaching critical severity and recur through weakness classes including improper certificate validation, input-validation gaps, cross-site scripting, certificate-host mismatch, and missing authorization controls that are characteristic of web-facing and federated data-handling systems. The vendor's narrow product footprint and enterprise deployment context mean that a single flaw can affect large, high-value customer bases despite the small number of distinct products tracked. Defenders should integrate this vendor's advisories into their patch cycles with attention to authentication and certificate management across data-integration tiers; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Palantir Technologies over time
Of all the CVEs published by Palantir Technologies as a CNA, 70.2% affect products that Palantir Technologies develops as a vendor.
Of all the CVEs published that affect products developed by Palantir Technologies, 100.0% are self-published by Palantir Technologies as a CNA.
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27889CRITICAL The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perf | Jun 14, 2022 | 9.1 | 29 | NO | NO |
CVE-2023-30945CRITICAL Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vuln | Jun 26, 2023 | 9.8 | 26 | NO | NO |
CVE-2022-27896HIGH Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating service log records of any Python c | Nov 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-30967HIGH Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. | Oct 26, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-27895HIGH Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This issue was present in versions e | Nov 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-27897HIGH Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly u | Feb 16, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-27892HIGH Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service. | Feb 16, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-27890HIGH It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privileg | Feb 16, 2023 | 7.4 | 23 | NO | NO |
CVE-2023-22835HIGH A security defect was identified that enabled a user of Foundry Issues to perform a Denial of Service attack by submitting malformed data in an Issue that caused loss of frontend f | Jul 10, 2023 | 7.7 | 22 | NO | NO |
CVE-2022-48306MEDIUM Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could | Feb 16, 2023 | 6.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Palantir Technologies.
Media articles that mention a CVE ID that affects a product developed by Palantir Technologies — matched by CVE ID, not by vendor name.