smnfbb
.
about
publications
advisories
contact
CVEs & Advisories
CVE-2026-50590 - Arbitrary File Access
June 2026
CVE-2024-4456 - Stored XSS in Audit Page
May 2024
CVE-2022-2416 - Blind SSRF vulnerability that allows enumeration/recon of an environment
July 2023
CVE-2022-2346 - Guest user with low permissions able to interact with extension endpoints
July 2023
CVE-2022-2074 - ReDoS in Variable Project Templates in Octopus Server
August 2022
CVE-2022-2049 - ReDoS in Package Upload Files in Octopus Server
August 2022
CVE-2022-2075 - ReDoS in Build Information request in Octopus Server
August 2022
CVE-2022-1881 - Insecure Direct Object Reference (IDOR) of Project Exports in Octopus Server
July 2022
CVE-2022-29890 - Stored Cross-Site Scripting (XSS) in Octopus Server help sidebar
July 2022
CVE-2021-43269 - Arbitrary code execution via malicious Code42 app proxy configuration
January 2022