{"schema_version":1,"title":"salt (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 72 vulnerabilities in salt (PyPI): 0 in the last 7 days and 14 in the last 90 days, 4 of them critical and 3 exploited in the wild. The most recent, CVE-2025-62348, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-salt","json_url":"https://junglewise.ai/threats/technologies/pypi-salt.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-salt","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":72,"critical":4,"exploited":3,"last_7_days":0,"last_30_days":0,"last_90_days":14,"last_365_days":15},"latest":[{"cve":"CVE-2025-62348","cvss":3.1,"epss":0.0019,"slug":"cve-2025-62348-salt-junos-module-vulnerable-to-code-injection-via-specially","title":"PYSEC-2026-1894 - Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:21.219152+00:00","url":"https://junglewise.ai/threats/cve-2025-62348-salt-junos-module-vulnerable-to-code-injection-via-specially"},{"cve":"CVE-2025-62349","cvss":3.1,"epss":0.0043,"slug":"cve-2025-62349-salt-authentication-protocol-version-downgrade-allows-minion","title":"PYSEC-2026-1902 - Salt Authentication Protocol Version Downgrade Allows Minion Impersonation","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:21.156662+00:00","url":"https://junglewise.ai/threats/cve-2025-62349-salt-authentication-protocol-version-downgrade-allows-minion"},{"cve":"CVE-2025-22242","cvss":3.1,"epss":0.0014,"slug":"cve-2025-22242-salt-s-worker-process-vulnerable-to-denial-of-service-through","title":"PYSEC-2026-1896 - Salt's worker process vulnerable to denial of service through file read operation","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.170211+00:00","url":"https://junglewise.ai/threats/cve-2025-22242-salt-s-worker-process-vulnerable-to-denial-of-service-through"},{"cve":"CVE-2025-22241","cvss":3.1,"epss":0.0018,"slug":"cve-2025-22241-salt-s-file-contents-overwrite-the-virtkey-class","title":"PYSEC-2026-1895 - Salt's file contents overwrite the VirtKey class","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.098993+00:00","url":"https://junglewise.ai/threats/cve-2025-22241-salt-s-file-contents-overwrite-the-virtkey-class"},{"cve":"CVE-2025-22237","cvss":3.1,"epss":0.0018,"slug":"cve-2025-22237-salt-s-on-demand-pillar-functionality-vulnerable-to-arbitrary","title":"PYSEC-2026-1898 - Salt's on demand pillar functionality vulnerable to arbitrary command injections","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.014568+00:00","url":"https://junglewise.ai/threats/cve-2025-22237-salt-s-on-demand-pillar-functionality-vulnerable-to-arbitrary"},{"cve":"CVE-2024-38825","cvss":3.1,"epss":0.0015,"slug":"cve-2024-38825-salt-s-salt-auth-pki-module-does-not-properly-authenticate","title":"PYSEC-2026-1893 - Salt's salt.auth.pki module does not properly authenticate callers","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.928384+00:00","url":"https://junglewise.ai/threats/cve-2024-38825-salt-s-salt-auth-pki-module-does-not-properly-authenticate"},{"cve":"CVE-2025-22240","cvss":3.1,"epss":0.0016,"slug":"cve-2025-22240-salt-allows-arbitrary-directory-creation-or-file-deletion","title":"PYSEC-2026-1903 - Salt allows arbitrary directory creation or file deletion","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.851955+00:00","url":"https://junglewise.ai/threats/cve-2025-22240-salt-allows-arbitrary-directory-creation-or-file-deletion"},{"cve":"CVE-2025-22238","cvss":3.1,"epss":0.0029,"slug":"cve-2025-22238-salt-vulnerable-to-directory-traversal-attack-in-minion-file","title":"PYSEC-2026-1901 - Salt vulnerable to directory traversal attack in minion file cache creation","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.775529+00:00","url":"https://junglewise.ai/threats/cve-2025-22238-salt-vulnerable-to-directory-traversal-attack-in-minion-file"},{"cve":"CVE-2025-22236","cvss":3.1,"epss":0.0017,"slug":"cve-2025-22236-salt-has-minion-event-bus-authorization-bypass-vulnerability","title":"PYSEC-2026-1899 - Salt has minion event bus authorization bypass vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.687467+00:00","url":"https://junglewise.ai/threats/cve-2025-22236-salt-has-minion-event-bus-authorization-bypass-vulnerability"},{"cve":"CVE-2025-22239","cvss":3.1,"epss":0.0018,"slug":"cve-2025-22239-salt-vulnerable-to-arbitrary-event-injection","title":"PYSEC-2026-1897 - Salt vulnerable to arbitrary event injection","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.610007+00:00","url":"https://junglewise.ai/threats/cve-2025-22239-salt-vulnerable-to-arbitrary-event-injection"},{"cve":"CVE-2023-34049","cvss":3.1,"epss":0.0019,"slug":"cve-2023-34049-salt-preflight-script-could-be-attacker-controlled","title":"PYSEC-2026-1892 - Salt preflight script could be attacker controlled","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:44.335132+00:00","url":"https://junglewise.ai/threats/cve-2023-34049-salt-preflight-script-could-be-attacker-controlled"},{"cve":"CVE-2024-22231","cvss":3.1,"epss":0.0069,"slug":"cve-2024-22231-directory-creation-by-malicious-user-in-saltstack","title":"PYSEC-2026-1900 - Directory creation by malicious user in saltstack","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:35.634149+00:00","url":"https://junglewise.ai/threats/cve-2024-22231-directory-creation-by-malicious-user-in-saltstack"},{"cve":"CVE-2024-22232","cvss":3.1,"epss":0.0084,"slug":"cve-2024-22232-saltstack-salt-path-traversal-in-file-server","title":"PYSEC-2026-1891 - Path traversal in saltstack","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:35.573683+00:00","url":"https://junglewise.ai/threats/cve-2024-22232-saltstack-salt-path-traversal-in-file-server"},{"cve":"CVE-2013-2228","cvss":3.1,"epss":0.0196,"slug":"cve-2013-2228-saltstack-rsa-key-generation-allows-remote-users-to-decrypt","title":"PYSEC-2026-748 - SaltStack RSA Key Generation allows remote users to decrypt communications","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:21.938484+00:00","url":"https://junglewise.ai/threats/cve-2013-2228-saltstack-rsa-key-generation-allows-remote-users-to-decrypt"},{"cve":"CVE-2024-38824","cvss":3.1,"epss":0.0101,"slug":"cve-2024-38824-salt-vulnerable-to-directory-traversal-attack-in-file-receiving","title":"PYSEC-2026-529 - Salt vulnerable to directory traversal attack in file receiving method","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:38.396059+00:00","url":"https://junglewise.ai/threats/cve-2024-38824-salt-vulnerable-to-directory-traversal-attack-in-file-receiving"},{"cve":"CVE-2023-20898","cvss":3.1,"epss":0.0032,"slug":"cve-2023-20898-salt-can-cause-git-providers-to-get-wrong-data","title":"PYSEC-2023-169 - Git Providers can read from the wrong environment because they get the same cache directory base name in Salt masters prior to 3005.2 or 300","severity":"low","exploited":false,"published_at":"2023-09-05T11:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-20898-salt-can-cause-git-providers-to-get-wrong-data"},{"cve":"CVE-2023-20897","cvss":3.1,"epss":0.0125,"slug":"cve-2023-20897-salt-vulnerable-to-denial-of-service","title":"PYSEC-2023-166 - Salt masters prior to 3005.2 or 3006.2 contain a DOS in minion return. After receiving several bad packets on the request server equal to th","severity":"low","exploited":false,"published_at":"2023-09-05T11:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-20897-salt-vulnerable-to-denial-of-service"},{"cve":"CVE-2021-33226","epss":0.0164,"slug":"cve-2021-33226-pysec-2023-47-buffer-overflow-vulnerability-in-saltstack-v-3003","title":"PYSEC-2023-47 - Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/mo","severity":"info","exploited":false,"published_at":"2023-02-17T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-33226-pysec-2023-47-buffer-overflow-vulnerability-in-saltstack-v-3003"},{"cve":"CVE-2022-22967","cvss":3.1,"epss":0.0212,"slug":"cve-2022-22967-salt-s-pam-auth-fails-to-reject-locked-accounts","title":"PYSEC-2022-210 - An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows","severity":"low","exploited":false,"published_at":"2022-06-23T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22967-salt-s-pam-auth-fails-to-reject-locked-accounts"},{"cve":"CVE-2017-12791","cvss":9.8,"epss":0.0467,"slug":"cve-2017-12791-saltstack-salt-directory-traversal-in-minion-id-validation","title":"SaltStack Salt directory traversal in minion id validation","severity":"critical","exploited":false,"published_at":"2022-05-17T01:22:50+00:00","url":"https://junglewise.ai/threats/cve-2017-12791-saltstack-salt-directory-traversal-in-minion-id-validation"},{"cve":"CVE-2022-22936","cvss":3.1,"epss":0.0083,"slug":"cve-2022-22936-saltstack-salt-authentication-bypass-by-capture-replay","title":"PYSEC-2022-173 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible t","severity":"low","exploited":false,"published_at":"2022-03-29T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22936-saltstack-salt-authentication-bypass-by-capture-replay"},{"cve":"CVE-2022-22935","cvss":3.1,"epss":0.0162,"slug":"cve-2022-22935-saltstack-salt-improper-authentication-via-man-in-the-middle","title":"PYSEC-2022-172 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a M","severity":"low","exploited":false,"published_at":"2022-03-29T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22935-saltstack-salt-improper-authentication-via-man-in-the-middle"},{"cve":"CVE-2022-22934","cvss":3.1,"epss":0.0088,"slug":"cve-2022-22934-saltstack-salt-improper-verification-of-cryptographic-signature","title":"PYSEC-2022-171 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s","severity":"low","exploited":false,"published_at":"2022-03-29T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22934-saltstack-salt-improper-verification-of-cryptographic-signature"},{"cve":"CVE-2022-22941","cvss":3.1,"epss":0.0135,"slug":"cve-2022-22941-saltstack-salt-permissions-bypass","title":"PYSEC-2022-174 - An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publishe","severity":"low","exploited":false,"published_at":"2022-03-29T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22941-saltstack-salt-permissions-bypass"},{"cve":"CVE-2021-21996","cvss":3.1,"epss":0.0351,"slug":"cve-2021-21996-exposure-of-resource-to-wrong-sphere-in-salt","title":"PYSEC-2021-318 - An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file syste","severity":"low","exploited":false,"published_at":"2021-09-08T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-21996-exposure-of-resource-to-wrong-sphere-in-salt"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":13},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"salt (PyPI)","slug":"pypi-salt","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Infrastructure automation and configuration management framework for Python.","url":"https://junglewise.ai/threats/technologies/pypi-salt"},"most_severe":[{"cve":"CVE-2020-16846","cvss":3.1,"epss":0.9959,"slug":"cve-2020-16846-saltstack-salt-shell-injection-vulnerability","title":"PYSEC-2020-104 - An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can resul","severity":"critical","exploited":true,"published_at":"2020-11-06T08:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-16846-saltstack-salt-shell-injection-vulnerability"},{"cve":"CVE-2020-11651","cvss":3.1,"epss":0.9661,"slug":"cve-2020-11651-saltstack-salt-authentication-bypass-vulnerability","title":"PYSEC-2020-102 - An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly","severity":"critical","exploited":true,"published_at":"2020-04-30T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-11651-saltstack-salt-authentication-bypass-vulnerability"},{"cve":"CVE-2020-11652","cvss":3.1,"epss":0.8618,"slug":"cve-2020-11652-saltstack-salt-path-traversal-vulnerability","title":"PYSEC-2020-103 - An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to","severity":"critical","exploited":true,"published_at":"2020-04-30T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-11652-saltstack-salt-path-traversal-vulnerability"},{"cve":"CVE-2017-12791","cvss":9.8,"epss":0.0467,"slug":"cve-2017-12791-saltstack-salt-directory-traversal-in-minion-id-validation","title":"SaltStack Salt directory traversal in minion id validation","severity":"critical","exploited":false,"published_at":"2022-05-17T01:22:50+00:00","url":"https://junglewise.ai/threats/cve-2017-12791-saltstack-salt-directory-traversal-in-minion-id-validation"},{"cve":"CVE-2021-25282","cvss":3.1,"epss":0.9241,"slug":"cve-2021-25282-saltstack-salt-directory-traversal-vulnerability","title":"PYSEC-2021-51 - An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory travers","severity":"low","exploited":false,"published_at":"2021-02-27T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-25282-saltstack-salt-directory-traversal-vulnerability"},{"cve":"CVE-2021-25281","cvss":3.1,"epss":0.7313,"slug":"cve-2021-25281-saltstack-salt-improper-authentication-vulnerability","title":"PYSEC-2021-50 - An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus","severity":"low","exploited":false,"published_at":"2021-02-27T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-25281-saltstack-salt-improper-authentication-vulnerability"},{"cve":"CVE-2021-3197","cvss":3.1,"epss":0.7233,"slug":"cve-2021-3197-saltstack-salt-is-vulnerable-to-shell-injection-via-proxycommand","title":"PYSEC-2021-57 - An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyComm","severity":"low","exploited":false,"published_at":"2021-02-27T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-3197-saltstack-salt-is-vulnerable-to-shell-injection-via-proxycommand"},{"cve":"CVE-2020-25592","cvss":3.1,"epss":0.5773,"slug":"cve-2020-25592-saltstack-salt-authentication-bypass-in-salt-netapi","title":"PYSEC-2020-106 - In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke S","severity":"low","exploited":false,"published_at":"2020-11-06T08:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-25592-saltstack-salt-authentication-bypass-in-salt-netapi"},{"cve":"CVE-2019-17361","cvss":3.1,"epss":0.1523,"slug":"cve-2019-17361-saltstack-salt-is-vulnerable-to-command-injection","title":"PYSEC-2020-177 - In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unau","severity":"low","exploited":false,"published_at":"2020-01-17T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2019-17361-saltstack-salt-is-vulnerable-to-command-injection"},{"cve":"CVE-2021-25283","cvss":3.1,"epss":0.1051,"slug":"cve-2021-25283-saltstack-salt-server-side-template-injection","title":"PYSEC-2021-52 - An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection","severity":"low","exploited":false,"published_at":"2021-02-27T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-25283-saltstack-salt-server-side-template-injection"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}