Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-16
10 active CVEs reported via OSV.dev
SaltStack Salt Improper Validation of eauth credentials and tokens in salt-netapi
SaltStack Improper Verification of Cryptographic Signature
Path traversal in saltstack
SaltStack Salt Allows creating certificates with weak file permissions
Salt preflight script could be attacker controlled
Salt's salt.auth.pki module does not properly authenticate callers
SaltStack Salt Authentication Bypass by Capture-replay
SaltStack Salt Denial of Service via a crafted authentication request
SaltStack has insecure /tmp file handling in salt/modules/chef.py
Salt uses weak permissions on the cache data
Get SLA-backed support, security patches, and direct access to senior engineers for SaltStack — without relying on volunteer maintainers.
Talk to an Expert →