Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.46% | — | SkipperAIOpenpolicyagent Open Policy AgentAI | 14/9/2026 | 16/9/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with… | |
| Aplazada | Alta (8.8) | 0.39% | — | Zalando SkipperAIOpenpolicyagent OPAAI | 23/7/2026 | 30/7/2026 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty… | |
| Aplazada | Alta (7.1) | 0.86% | — | EnvoyAIOpenpolicyagent OPA Envoy PluginAI | 19/2/2026 | 17/6/2026 | opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority… | |
| Aplazada | Alta (7.4) | 0.53% | — | Openpolicyagent OPAAI | 1/5/2025 | 17/6/2026 | Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API for reading and writing documents. Requesting a virtual document through the Data API entails policy evaluation, where a Rego query containing a single data document… | |
| Analizada | Alta (7.3) | 0.34% | — | Openpolicyagent Open Policy Agent | 30/8/2024 | 17/6/2026 | A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. | |
| Modificada | Crítica (9.8) | 1.6% | — | Openpolicyagent Open Policy Agent | 8/9/2022 | 17/6/2026 | Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejected — by the compiler if encountered in the policy compilation… | |
| Modificada | Alta (7.5) | 1.7% | — | Openpolicyagent Open Policy Agent | 30/6/2022 | 17/6/2026 | An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Alta (7.5) | 1.0% | — | Openpolicyagent Open Policy Agent | 19/5/2022 | 17/6/2026 | An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access. | |
| Modificada | Media (5.3) | 1.0% | — | Openpolicyagent Open Policy Agent | 9/2/2022 | 17/6/2026 | OPA is an open source, general-purpose policy engine. Under certain conditions, pretty-printing an abstract syntax tree (AST) that contains synthetic nodes could change the logic of some statements by reordering array literals. Example of policies impacted are those that parse and compare web paths. **All of these**… | |
| Modificada | Media (5.3) | 1.1% | — | Openpolicyagent Gatekeeper | 17/11/2021 | 17/6/2026 | Styra Open Policy Agent (OPA) Gatekeeper through 3.7.0 mishandles concurrency, sometimes resulting in incorrect access control. The data replication mechanism allows policies to access the Kubernetes cluster state. During data replication, OPA/Gatekeeper does not wait for the replication to finish before processing a… |