Serverpod is a modestly represented backend-as-a-service framework where its narrow disclosure profile clusters around its single namesake product and centers on cryptographic and authentication boundary issues. The recurring weakness classes—improper certificate validation and insufficient computational effort in password hashing—reflect the security-critical decisions inherent to server-side frameworks handling credential exchange and TLS integrity. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Serverpod over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29887HIGH Serverpod is an app and web server, built for the Flutter and Dart ecosystem. This bug bypassed the validation of TSL certificates on all none web HTTP clients in the `serverpod_cl | Mar 27, 2024 | 7.4 | 19 | NO | NO |
CVE-2024-29886MEDIUM Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that made it susceptible to rainbow attac | Mar 27, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Serverpod.
Media articles that mention a CVE ID that affects a product developed by Serverpod — matched by CVE ID, not by vendor name.