OSS Support Hub / Infrastructure

Python Infrastructure

SaltStack

Event-driven IT automation, remote execution, and configuration management

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

GitHub Stars
📦
Latest Release
🔄
Avg. Release Cadence
🐛
Open Issues
📅
Unknown
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-05-16

Known Vulnerabilities

10 active CVEs reported via OSV.dev

SaltStack Salt Improper Validation of eauth credentials and tokens in salt-netapi

Published: 2022-05-24 Fixed in: 2015.8.13

SaltStack Improper Verification of Cryptographic Signature

Published: 2022-03-30 Fixed in: 3002.8

Path traversal in saltstack

Published: 2024-06-27 Fixed in: 3005.5

SaltStack Salt Allows creating certificates with weak file permissions

Published: 2022-05-24 Fixed in: 2015.8.13

Salt preflight script could be attacker controlled

Published: 2024-11-14 Fixed in: 3005.4

Salt's salt.auth.pki module does not properly authenticate callers

Published: 2025-06-13 Fixed in: 3006.12

SaltStack Salt Authentication Bypass by Capture-replay

Published: 2022-03-30 Fixed in: 3002.8

SaltStack Salt Denial of Service via a crafted authentication request

Published: 2022-05-17 Fixed in: 2016.3.8

SaltStack has insecure /tmp file handling in salt/modules/chef.py

Published: 2022-05-17 Fixed in: 2014.7.4

Salt uses weak permissions on the cache data

Published: 2022-05-17 Fixed in: 2015.8.3

Alternatives to SaltStack

Other Infrastructure projects in the Python ecosystem worth evaluating.

Support Options for SaltStack

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for SaltStack — without relying on volunteer maintainers.

Talk to an Expert →