Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sylabs

First CVE: Jul 5, 2018Active for: 8 yearsTotal CVEs: 18
43.0
VTI Score
High

Sylabs develops Singularity, a container platform widely used in high-performance computing and research environments, alongside related image-format and registry products that together present a concentrated but strategically important attack surface. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through weakness classes centered on input validation, resource-access control, and cryptographic-signature verification—issues that are particularly consequential in container-image authentication and supply-chain integrity. Defenders relying on Singularity should prioritize patch deployment and validate the integrity of container images from untrusted sources; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sylabs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2018
8 years ago
Most Recent CVE
Apr 25, 2023
1,186 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-39237CRITICAL
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the h
Oct 6, 20229.832NONO
CVE-2021-33027CRITICAL
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
Jul 19, 20219.830NONO
CVE-2021-33622CRITICAL
Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.
Jun 15, 20219.828NONO
CVE-2019-11328HIGH
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure
May 14, 20198.828NONO
CVE-2020-25040HIGH
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020
Sep 16, 20208.827NONO
CVE-2020-25039HIGH
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
Sep 16, 20208.126NONO
CVE-2020-13847HIGH
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descr
Jul 14, 20207.525NONO
CVE-2020-13846HIGH
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
Jul 14, 20207.525NONO
CVE-2023-30549HIGH
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that incl
Apr 25, 20237.824NONO
CVE-2022-23538HIGH
github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a containe
Jan 17, 20237.624NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
17%
61%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (16.7%)
Network15 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required3 (16.7%)
Privileges Required
Low8 (44.4%)
High0 (0.0%)
None10 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sylabs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sylabs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sylabs's Products

View all 2 CNAs →

Top CWEs