Sylabs develops Singularity, a container platform widely used in high-performance computing and research environments, alongside related image-format and registry products that together present a concentrated but strategically important attack surface. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through weakness classes centered on input validation, resource-access control, and cryptographic-signature verification—issues that are particularly consequential in container-image authentication and supply-chain integrity. Defenders relying on Singularity should prioritize patch deployment and validate the integrity of container images from untrusted sources; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sylabs over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39237CRITICAL syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the h | Oct 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-33027CRITICAL Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce. | Jul 19, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-33622CRITICAL Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value. | Jun 15, 2021 | 9.8 | 28 | NO | NO |
CVE-2019-11328HIGH An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure | May 14, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-25040HIGH Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020 | Sep 16, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-25039HIGH Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. | Sep 16, 2020 | 8.1 | 26 | NO | NO |
CVE-2020-13847HIGH Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descr | Jul 14, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-13846HIGH Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code. | Jul 14, 2020 | 7.5 | 25 | NO | NO |
CVE-2023-30549HIGH Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that incl | Apr 25, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-23538HIGH github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a containe | Jan 17, 2023 | 7.6 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sylabs.
Media articles that mention a CVE ID that affects a product developed by Sylabs — matched by CVE ID, not by vendor name.