Runatlantis develops Atlantis, a pull-request automation tool for infrastructure-as-code workflows that integrates with version-control platforms to manage Terraform deployments. The vendor's observed vulnerability signals center on information-disclosure and logging-related weaknesses, reflecting the sensitive credentials and operational context that flow through the tool's request and state handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Runatlantis over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52009CRITICAL Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are | Nov 8, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-58445HIGH Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information thro | Sep 6, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-24912HIGH The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in the webhook event validator code, which does not use a consta | Jul 29, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Runatlantis.
Media articles that mention a CVE ID that affects a product developed by Runatlantis — matched by CVE ID, not by vendor name.