Ceph Storage
Vendor:
First CVE: Oct 3, 2016 · Active for 9 years
45
Total CVEs
More Total CVEs than 97% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
2.2%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ceph Storage over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2016
9 years ago
Most Recent CVE
Dec 18, 2025
218 days ago
CVE Severity & Scoring
Ceph Storage45 CVEs
51%
33%
16%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (22.2%)
Network30 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (11.1%)
Attack Complexity
Low41 (91.1%)
High4 (8.9%)
Unknown0 (0.0%)
User Interaction
None38 (84.4%)
Unknown0 (0.0%)
Required7 (15.6%)
Privileges Required
Low14 (31.1%)
High3 (6.7%)
None28 (62.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2018-15727CRITICAL Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an | Aug 29, 2018 | 9.8 | 76 | NO | YES |
CVE-2022-26148CRITICAL An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a | Mar 21, 2022 | 9.8 | 73 | NO | YES |
CVE-2018-14649CRITICAL It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin | Oct 9, 2018 | 9.8 | 36 | NO | NO |
CVE-2025-13601HIGH A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a ver | Nov 26, 2025 | 7.7 | 30 | NO | NO |
CVE-2021-4048CRITICAL An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially | Dec 8, 2021 | 9.1 | 30 | NO | NO |
CVE-2021-20236CRITICAL A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscrip | May 28, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-0670CRITICAL A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to | Jul 25, 2022 | 9.1 | 29 | NO | NO |
CVE-2019-14859CRITICAL A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signatur | Jan 2, 2020 | 9.1 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (45 CVEs).
CISA KEV
1 CVE
2.2% of CVEs· 96th percentile
Metasploit
1 CVE
2.2% of CVEs· 96th percentile
Nuclei
2 CVEs
4.4% of CVEs· 97th percentile
ExploitDB
1 CVE
2.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (45 CVEs).
Media Mentions
Signals from CVEs in this product scope (45 CVEs).
Top CNAs Publishing CVEs For Ceph Storage
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 2 | 7.6 | 0.4% | 0 | 0 |
| 6.0 | 1 | 5.9 | 93.3% | 0 | 1 |
| 5.1 | 1 | 6.5 | 0.4% | 0 | 0 |
| 5.0 | 6 | 7.5 | 22.8% | 1 | 2 |
| 4.3 | 1 | 6.5 | 0.4% | 0 | 0 |
| 4.0 | 18 | 6.8 | 3.9% | 0 | 1 |
| 3.3 | 2 | 7.0 | 3.0% | 0 | 0 |
| 3.0 | 22 | 7.1 | 7.2% | 0 | 2 |
| 3 | 3 | 7.4 | 2.2% | 0 | 0 |
| 2.0 | 13 | 7.7 | 2.2% | 0 | 0 |
| 1.3 | 2 | 7.2 | 3.6% | 0 | 0 |