Tyk develops an API gateway and identity management platform widely deployed in enterprise API orchestration and authentication layers, with a compact product portfolio centered on its core gateway and identity-broker components. The observed vulnerabilities cluster around input-validation and authentication-handling issues, including SQL injection, improper authentication mechanisms, and path-traversal conditions that reflect the attack surface inherent to gateway and authentication services. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tyk over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42284CRITICAL Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | Nov 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-42283CRITICAL Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | Nov 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-23365CRITICAL The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. Th | Apr 26, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-23357MEDIUM All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function. This function is able to delete arbitrar | Mar 15, 2021 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tyk.
Media articles that mention a CVE ID that affects a product developed by Tyk — matched by CVE ID, not by vendor name.