Siderolabs develops specialized Kubernetes and container infrastructure products, including the Talos Linux operating system and Omni management platform, that serve niche but critical roles in cloud-native deployment. Its vulnerability surface centers on authorization, information disclosure, permission handling, and error-condition logic—patterns characteristic of systems that mediate access and state across distributed infrastructure components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Siderolabs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36103HIGH Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due to improper validation of the | Sep 13, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-61688HIGH Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API. | Oct 13, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-59836HIGH Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allo | Oct 13, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-59824MEDIUM Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni and each Talos machine | Sep 24, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Siderolabs.
Media articles that mention a CVE ID that affects a product developed by Siderolabs — matched by CVE ID, not by vendor name.