Technology · PyPI
salt (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 72 vulnerabilities in salt (PyPI): 0 in the last 7 days and 14 in the last 90 days, 4 of them critical and 3 exploited in the wild. The most recent, CVE-2025-62348, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 14
- Critical, all time
- 4
- Exploited in the wild
- 3
About salt (PyPI)
Infrastructure automation and configuration management framework for Python.
Latest salt (PyPI) vulnerabilities
- CVE-2025-62348: PYSEC-2026-1894 - Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML PayloadlowCVSS 3.1EPSS 0.2%
- CVE-2025-62349: PYSEC-2026-1902 - Salt Authentication Protocol Version Downgrade Allows Minion ImpersonationlowCVSS 3.1EPSS 0.4%
- CVE-2025-22242: PYSEC-2026-1896 - Salt's worker process vulnerable to denial of service through file read operationlowCVSS 3.1EPSS 0.1%
- CVE-2025-22241: PYSEC-2026-1895 - Salt's file contents overwrite the VirtKey classlowCVSS 3.1EPSS 0.2%
- CVE-2025-22237: PYSEC-2026-1898 - Salt's on demand pillar functionality vulnerable to arbitrary command injectionslowCVSS 3.1EPSS 0.2%
- CVE-2024-38825: PYSEC-2026-1893 - Salt's salt.auth.pki module does not properly authenticate callerslowCVSS 3.1EPSS 0.1%
- CVE-2025-22240: PYSEC-2026-1903 - Salt allows arbitrary directory creation or file deletionlowCVSS 3.1EPSS 0.2%
- CVE-2025-22238: PYSEC-2026-1901 - Salt vulnerable to directory traversal attack in minion file cache creationlowCVSS 3.1EPSS 0.3%
- CVE-2025-22236: PYSEC-2026-1899 - Salt has minion event bus authorization bypass vulnerabilitylowCVSS 3.1EPSS 0.2%
- CVE-2025-22239: PYSEC-2026-1897 - Salt vulnerable to arbitrary event injectionlowCVSS 3.1EPSS 0.2%
- CVE-2023-34049: PYSEC-2026-1892 - Salt preflight script could be attacker controlledlowCVSS 3.1EPSS 0.2%
- CVE-2024-22231: PYSEC-2026-1900 - Directory creation by malicious user in saltstacklowCVSS 3.1EPSS 0.7%
- CVE-2024-22232: PYSEC-2026-1891 - Path traversal in saltstacklowCVSS 3.1EPSS 0.8%
- CVE-2013-2228: PYSEC-2026-748 - SaltStack RSA Key Generation allows remote users to decrypt communicationslowCVSS 3.1EPSS 2.0%
- CVE-2024-38824: PYSEC-2026-529 - Salt vulnerable to directory traversal attack in file receiving methodlowCVSS 3.1EPSS 1.0%
- CVE-2023-20898: PYSEC-2023-169 - Git Providers can read from the wrong environment because they get the same cache directory base name in…lowCVSS 3.1EPSS 0.3%
- CVE-2023-20897: PYSEC-2023-166 - Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad…lowCVSS 3.1EPSS 1.3%
- CVE-2021-33226: PYSEC-2023-47 - Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via…infoEPSS 1.6%
- CVE-2022-22967: PYSEC-2022-210 - An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to…lowCVSS 3.1EPSS 2.1%
- CVE-2017-12791: SaltStack Salt directory traversal in minion id validationcriticalCVSS 9.8EPSS 4.7%
- CVE-2022-22936: PYSEC-2022-173 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and…lowCVSS 3.1EPSS 0.8%
- CVE-2022-22935: PYSEC-2022-172 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion…lowCVSS 3.1EPSS 1.6%
- CVE-2022-22934: PYSEC-2022-171 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not…lowCVSS 3.1EPSS 0.9%
- CVE-2022-22941: PYSEC-2022-174 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a…lowCVSS 3.1EPSS 1.4%
- CVE-2021-21996: PYSEC-2021-318 - An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and…lowCVSS 3.1EPSS 3.5%
Most severe salt (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-16846: PYSEC-2020-104 - An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API…criticalexploited in the wildCVSS 3.1EPSS 99.6%
- CVE-2020-11651: PYSEC-2020-102 - An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process…criticalexploited in the wildCVSS 3.1EPSS 96.6%
- CVE-2020-11652: PYSEC-2020-103 - An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process…criticalexploited in the wildCVSS 3.1EPSS 86.2%
- CVE-2017-12791: SaltStack Salt directory traversal in minion id validationcriticalCVSS 9.8EPSS 4.7%
- CVE-2021-25282: PYSEC-2021-51 - An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method…lowCVSS 3.1EPSS 92.4%
- CVE-2021-25281: PYSEC-2021-50 - An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials…lowCVSS 3.1EPSS 73.1%
- CVE-2021-3197: PYSEC-2021-57 - An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell…lowCVSS 3.1EPSS 72.3%
- CVE-2020-25592: PYSEC-2020-106 - In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can…lowCVSS 3.1EPSS 57.7%
- CVE-2019-17361: PYSEC-2020-177 - In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to…lowCVSS 3.1EPSS 15.2%
- CVE-2021-25283: PYSEC-2021-52 - An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect…lowCVSS 3.1EPSS 10.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 13 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-salt.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "salt (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-salt, 28 September 2026.