Netapp
Netapp Storagegrid: vulnerabilities and CVEs
Netapp Storagegrid has 75 published vulnerabilities, 3 of them in the last 12 months. 9 are rated critical and 2 are listed by CISA as actively exploited.
CVEs75
Last 12 months3
Critical9
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3427 | Critical (9.8) | 92% | ⚠ Active exploitation | Apr 21, 2016 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
| CVE-2021-40438 | Critical (9) | 100% | ⚠ Active exploitation | Sep 16, 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22056 | Low (2.3) | 0.25% | — | Aug 28, 2026 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with… |
| CVE-2026-22051 | Low (2.3) | 0.18% | — | Apr 20, 2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low… |
| CVE-2026-22048 | High (7.1) | 0.28% | — | Feb 18, 2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side… |
| CVE-2025-26517 | Medium (5.4) | 0.19% | — | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege escalation vulnerability. Successful exploit could allow an unauthorized authenticated attacker to… |
| CVE-2025-26516 | Medium (5.3) | 0.39% | — | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an unauthenticated attacker to cause a Denial of… |
| CVE-2025-26515 | High (7.5) | 0.34% | — | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 without Single Sign-on enabled are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow… |
| CVE-2025-26514 | Medium (6.4) | 0.24% | — | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify… |
| CVE-2025-25292 | Critical (9.3) | 65% | — | Mar 12, 2025 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential.… |
| CVE-2025-25291 | Critical (9.3) | 21% | — | Mar 12, 2025 | ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential.… |
| CVE-2024-21994 | Medium (4.3) | 0.36% | — | Nov 8, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to a service crash. |
| CVE-2024-21988 | Medium (5.3) | 0.24% | — | Jun 14, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic… |
| CVE-2024-21984 | Medium (6.9) | 0.31% | — | Feb 16, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a difficult to exploit Reflected Cross-Site Scripting (XSS) vulnerability. Successful exploit requires the attacker to know specific… |
| CVE-2024-21983 | Medium (6.5) | 0.49% | — | Feb 16, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead to an out of memory condition or… |
| CVE-2023-27318 | High (7.5) | 0.70% | — | Feb 5, 2024 | StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash of the Local Distribution Router (LDR)… |
| CVE-2022-38734 | High (7.5) | 0.62% | — | Mar 2, 2023 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to to a crash of the Local Distribution Router (LDR)… |
| CVE-2022-23238 | Medium (6.5) | 0.72% | — | Aug 10, 2022 | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote… |
| CVE-2022-37434 | Critical (9.8) | 19% | — | Aug 5, 2022 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common… |
| CVE-2022-1678 | High (7.5) | 2.9% | — | May 25, 2022 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. |
| CVE-2022-0778 | High (7.5) | 73% | — | Mar 15, 2022 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic… |
| CVE-2022-23233 | High (7.5) | 0.93% | — | Mar 4, 2022 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distribution Router (LDR)… |
| CVE-2022-23232 | Medium (4.9) | 0.77% | — | Mar 4, 2022 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data… |
| CVE-2022-23806 | Critical (9.1) | 3.1% | — | Feb 11, 2022 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. |
| CVE-2022-23773 | High (7.5) | 2.7% | — | Feb 11, 2022 | cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches… |
| CVE-2022-23772 | High (7.5) | 2.8% | — | Feb 11, 2022 | Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. |
| CVE-2021-27006 | Medium (4.4) | 0.26% | — | Dec 23, 2021 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System… |
| CVE-2021-40438 | Critical (9) | 100% | ⚠ Active exploitation | Sep 16, 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
| CVE-2021-39275 | Critical (9.8) | 39% | — | Sep 16, 2021 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP… |
| CVE-2021-36160 | High (7.5) | 63% | — | Sep 16, 2021 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). |
| CVE-2021-34798 | High (7.5) | 65% | — | Sep 16, 2021 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. |
| CVE-2021-34558 | Medium (6.5) | 7.0% | — | Jul 15, 2021 | The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to… |
Other products by Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H300s Firmware · 292H500s Firmware · 292H410s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211