The number and severity of CVEs published that impact products developed by Shellhub over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44426MEDIUM ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including
the members list (user IDs, e-mails, roles), setti | May 13, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-44424MEDIUM ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, without verifying that the device | May 13, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-44423MEDIUM ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without scoping by the caller's tenant. | May 13, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-44425MEDIUM ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-enc | May 13, 2026 | 5.4 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shellhub.
Media articles that mention a CVE ID that affects a product developed by Shellhub — matched by CVE ID, not by vendor name.