The SKS Keyserver Project maintains a specialized public-key infrastructure service used for distributing and retrieving OpenPGP keys, with a narrow but critical deployment footprint across security and email infrastructure. The observed vulnerability profile centers on its single keyserver product and recurs through weakness classes including improper certificate validation and cross-site scripting issues, reflecting the authentication and web-interface demands of a key-distribution service. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sks Keyserver Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13050HIGH Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referri | Jun 29, 2019 | 7.5 | 26 | NO | NO |
CVE-2014-3207MEDIUM Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/ | May 8, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sks Keyserver Project.
Media articles that mention a CVE ID that affects a product developed by Sks Keyserver Project — matched by CVE ID, not by vendor name.