{"schema_version":1,"title":"keylime (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in keylime (PyPI): 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2023-38200, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/keylime","json_url":"https://junglewise.ai/threats/technologies/keylime.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/keylime","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":6},"latest":[{"cve":"CVE-2023-38200","cvss":3.1,"epss":0.0145,"slug":"cve-2023-38200-keylime-s-registrar-vulnerable-to-denial-of-service-attack-via-a","title":"PYSEC-2026-1489 - Keylime's registrar vulnerable to Denial-of-service attack via a single open connection","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:21.483576+00:00","url":"https://junglewise.ai/threats/cve-2023-38200-keylime-s-registrar-vulnerable-to-denial-of-service-attack-via-a"},{"cvss":6.3,"slug":"keylime-security-bypass-via-hardcoded-tpm-attestation-nonce-16dcb84a","title":"Keylime security bypass via hardcoded TPM attestation nonce","severity":"medium","exploited":false,"published_at":"2026-05-06T12:30:28+00:00","url":"https://junglewise.ai/threats/keylime-security-bypass-via-hardcoded-tpm-attestation-nonce-16dcb84a"},{"cve":"CVE-2026-6420","cvss":6.3,"epss":0.0018,"slug":"cve-2026-6420-keylime-security-bypass-via-hardcoded-tpm-quote-nonce","title":"Keylime security bypass via hardcoded TPM quote nonce","severity":"medium","exploited":false,"published_at":"2026-05-06T11:16:05.193+00:00","url":"https://junglewise.ai/threats/cve-2026-6420-keylime-security-bypass-via-hardcoded-tpm-quote-nonce"},{"cvss":3.1,"slug":"keylime-registrar-authentication-bypass-via-missing-tls-validation-f26498d5","title":"Keylime registrar authentication bypass via missing TLS validation","severity":"low","exploited":false,"published_at":"2026-02-06T21:30:49+00:00","url":"https://junglewise.ai/threats/keylime-registrar-authentication-bypass-via-missing-tls-validation-f26498d5"},{"cve":"CVE-2026-1709","cvss":9.4,"epss":0.0553,"slug":"cve-2026-1709-keylime-authentication-bypass-in-registrar-component","title":"Keylime authentication bypass in registrar component","severity":"critical","exploited":false,"published_at":"2026-02-06T20:16:09.193+00:00","url":"https://junglewise.ai/threats/cve-2026-1709-keylime-authentication-bypass-in-registrar-component"},{"cve":"CVE-2025-13609","cvss":8.2,"epss":0.0044,"slug":"cve-2025-13609-keylime-identity-takeover-via-duplicate-uuid-registration-in","title":"Keylime identity takeover via duplicate UUID registration in Registrar","severity":"high","exploited":false,"published_at":"2025-11-24T18:15:49.83+00:00","url":"https://junglewise.ai/threats/cve-2025-13609-keylime-identity-takeover-via-duplicate-uuid-registration-in"},{"cve":"CVE-2025-1057","cvss":4.3,"epss":0.0039,"slug":"cve-2025-1057-keylime-registrar-denial-of-service-during-version-update","title":"Keylime registrar denial of service during version update","severity":"medium","exploited":false,"published_at":"2025-02-14T18:03:14+00:00","url":"https://junglewise.ai/threats/cve-2025-1057-keylime-registrar-denial-of-service-during-version-update"},{"cve":"CVE-2023-38201","cvss":3.1,"epss":0.0049,"slug":"cve-2023-38201-keylime-registrar-and-untrusted-agent-can-be-bypassed-by-an","title":"PYSEC-2023-160 - A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue","severity":"low","exploited":false,"published_at":"2023-08-25T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38201-keylime-registrar-and-untrusted-agent-can-be-bypassed-by-an"},{"cve":"CVE-2023-3674","cvss":3.1,"epss":0.0021,"slug":"cve-2023-3674-keylime-fails-to-flag-device-as-untrusted-when-signature-does-not","title":"PYSEC-2023-128 - A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signatur","severity":"low","exploited":false,"published_at":"2023-07-19T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-3674-keylime-fails-to-flag-device-as-untrusted-when-signature-does-not"},{"cve":"CVE-2022-3500","cvss":3.1,"epss":0.0026,"slug":"cve-2022-3500-keylime-unhandled-exceptions-could-lead-to-invalid-attestation","title":"PYSEC-2022-42995 - A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there ex","severity":"low","exploited":false,"published_at":"2022-11-22T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3500-keylime-unhandled-exceptions-could-lead-to-invalid-attestation"},{"cve":"CVE-2022-1053","cvss":3.1,"epss":0.0145,"slug":"cve-2022-1053-tenant-and-verifier-might-not-use-the-same-registrar-data","title":"PYSEC-2022-184 - Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and t","severity":"low","exploited":false,"published_at":"2022-05-06T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1053-tenant-and-verifier-might-not-use-the-same-registrar-data"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"keylime (PyPI)","slug":"keylime","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://keylime.dev/","repo_url":"https://github.com/keylime/keylime","description":"A remote boot attestation and integrity management solution using Trusted Platform Modules.","url":"https://junglewise.ai/threats/technologies/keylime"},"most_severe":[{"cve":"CVE-2026-1709","cvss":9.4,"epss":0.0553,"slug":"cve-2026-1709-keylime-authentication-bypass-in-registrar-component","title":"Keylime authentication bypass in registrar component","severity":"critical","exploited":false,"published_at":"2026-02-06T20:16:09.193+00:00","url":"https://junglewise.ai/threats/cve-2026-1709-keylime-authentication-bypass-in-registrar-component"},{"cve":"CVE-2025-13609","cvss":8.2,"epss":0.0044,"slug":"cve-2025-13609-keylime-identity-takeover-via-duplicate-uuid-registration-in","title":"Keylime identity takeover via duplicate UUID registration in Registrar","severity":"high","exploited":false,"published_at":"2025-11-24T18:15:49.83+00:00","url":"https://junglewise.ai/threats/cve-2025-13609-keylime-identity-takeover-via-duplicate-uuid-registration-in"},{"cve":"CVE-2026-6420","cvss":6.3,"epss":0.0018,"slug":"cve-2026-6420-keylime-security-bypass-via-hardcoded-tpm-quote-nonce","title":"Keylime security bypass via hardcoded TPM quote nonce","severity":"medium","exploited":false,"published_at":"2026-05-06T11:16:05.193+00:00","url":"https://junglewise.ai/threats/cve-2026-6420-keylime-security-bypass-via-hardcoded-tpm-quote-nonce"},{"cvss":6.3,"slug":"keylime-security-bypass-via-hardcoded-tpm-attestation-nonce-16dcb84a","title":"Keylime security bypass via hardcoded TPM attestation nonce","severity":"medium","exploited":false,"published_at":"2026-05-06T12:30:28+00:00","url":"https://junglewise.ai/threats/keylime-security-bypass-via-hardcoded-tpm-attestation-nonce-16dcb84a"},{"cve":"CVE-2025-1057","cvss":4.3,"epss":0.0039,"slug":"cve-2025-1057-keylime-registrar-denial-of-service-during-version-update","title":"Keylime registrar denial of service during version update","severity":"medium","exploited":false,"published_at":"2025-02-14T18:03:14+00:00","url":"https://junglewise.ai/threats/cve-2025-1057-keylime-registrar-denial-of-service-during-version-update"},{"cve":"CVE-2023-38200","cvss":3.1,"epss":0.0145,"slug":"cve-2023-38200-keylime-s-registrar-vulnerable-to-denial-of-service-attack-via-a","title":"PYSEC-2026-1489 - Keylime's registrar vulnerable to Denial-of-service attack via a single open connection","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:21.483576+00:00","url":"https://junglewise.ai/threats/cve-2023-38200-keylime-s-registrar-vulnerable-to-denial-of-service-attack-via-a"},{"cve":"CVE-2022-1053","cvss":3.1,"epss":0.0145,"slug":"cve-2022-1053-tenant-and-verifier-might-not-use-the-same-registrar-data","title":"PYSEC-2022-184 - Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and t","severity":"low","exploited":false,"published_at":"2022-05-06T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1053-tenant-and-verifier-might-not-use-the-same-registrar-data"},{"cve":"CVE-2023-38201","cvss":3.1,"epss":0.0049,"slug":"cve-2023-38201-keylime-registrar-and-untrusted-agent-can-be-bypassed-by-an","title":"PYSEC-2023-160 - A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue","severity":"low","exploited":false,"published_at":"2023-08-25T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38201-keylime-registrar-and-untrusted-agent-can-be-bypassed-by-an"},{"cve":"CVE-2022-3500","cvss":3.1,"epss":0.0026,"slug":"cve-2022-3500-keylime-unhandled-exceptions-could-lead-to-invalid-attestation","title":"PYSEC-2022-42995 - A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there ex","severity":"low","exploited":false,"published_at":"2022-11-22T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3500-keylime-unhandled-exceptions-could-lead-to-invalid-attestation"},{"cve":"CVE-2023-3674","cvss":3.1,"epss":0.0021,"slug":"cve-2023-3674-keylime-fails-to-flag-device-as-untrusted-when-signature-does-not","title":"PYSEC-2023-128 - A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signatur","severity":"low","exploited":false,"published_at":"2023-07-19T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-3674-keylime-fails-to-flag-device-as-untrusted-when-signature-does-not"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}