Talend operates a widely deployed data integration and metadata management platform spanning data cataloging, administration, and enterprise service bus components that sit in data pipelines and governance workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including XML external entity injection, authentication and access-control failures, and path traversal in configuration and metadata-handling logic that reflects the platform's role in managing sensitive data flows and administrative functions. Defenders should prioritize patching this vendor's advisories for internet-facing or authenticated administrative endpoints; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Talend over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42837CRITICAL An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user f | Nov 5, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-4311CRITICAL A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handler. The manipulation leads to x | Jan 9, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-40684CRITICAL Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of | Sep 22, 2021 | 9.1 | 28 | NO | NO |
CVE-2022-45588HIGH All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or | Feb 3, 2023 | 7.8 | 27 | NO | NO |
CVE-2022-45589HIGH All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of | Feb 6, 2023 | 7.2 | 25 | NO | NO |
CVE-2014-2228CRITICAL The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages. | Feb 19, 2020 | 9.8 | 25 | NO | NO |
CVE-2012-2656HIGH An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information. | Dec 18, 2019 | 7.5 | 25 | NO | NO |
CVE-2023-31444HIGH In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote | Apr 28, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-33247HIGH Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is | May 26, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-29943MEDIUM Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access as root on the remote filesyst | May 4, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Talend.
Media articles that mention a CVE ID that affects a product developed by Talend — matched by CVE ID, not by vendor name.