Zstack is a modestly represented infrastructure-automation and cloud-management platform whose vulnerability footprint centers on its core product and REST API surface. The recurring weaknesses—code injection, untrusted deserialization, authorization failures, and session-management issues—reflect the risks inherent to API-driven infrastructure control, where flaws in input handling and access logic can propagate across managed systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zstack over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32829CRITICAL ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versio | Aug 17, 2021 | 9.9 | 31 | NO | NO |
CVE-2021-32836HIGH ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST A | Sep 9, 2021 | 8.1 | 26 | NO | NO |
CVE-2023-46326HIGH ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the session ID for each of these. This leads to privilege escalation. | Nov 30, 2023 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zstack.
Media articles that mention a CVE ID that affects a product developed by Zstack — matched by CVE ID, not by vendor name.