VendorsCloud Foundryboshall versions
Vulnerabilities

Cloud Foundry Bosh

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-4961
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
Published 2017-06-13 · Modified
8.8EPSS 0.005
CVE-2018-11083
Bosh accepts refresh tokens in place of an access token
Published 2018-10-05 · Modified
8.4EPSS 0.015
CVE-2019-11271
Bosh Deployment logs leak sensitive information
Published 2019-06-18 · Modified
7.8EPSS 0.003
CVE-2026-41704
Compromised VM can make arbitrary blobstore deletes
Published 2026-05-27 · Analyzed
6.8EPSS 0.001
CVE-2026-41009
Local Blobstore may allow arbitrary reads/deletes
Published 2026-05-27 · Analyzed
5.8EPSS 0.001