Reproducible Builds is a project focused on enabling deterministic, verifiable software builds, with a narrow product footprint centered on the diffoscope utility for comparing binary artifacts and detecting unauthorized modifications. Observed vulnerabilities in this domain center on path-traversal conditions that could arise during file analysis and comparison operations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Reproducible Builds over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0359CRITICAL diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. | Apr 13, 2018 | 9.8 | 24 | NO | NO |
CVE-2024-25711HIGH diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs | Feb 27, 2024 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Reproducible Builds.
Media articles that mention a CVE ID that affects a product developed by Reproducible Builds — matched by CVE ID, not by vendor name.