{"schema_version":1,"title":"Linuxfoundation vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Linuxfoundation: 0 in the last 7 days and 0 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-37532, was published on 1 May 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/linuxfoundation","json_url":"https://junglewise.ai/threats/vendors/linuxfoundation.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/linuxfoundation","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":10,"all_time":16,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":16},"latest":[{"cve":"CVE-2026-37532","cvss":7.1,"slug":"cve-2026-37532-automotive-grade-linux-agl-service-can-low-level-heap-over-read","title":"Automotive Grade Linux agl-service-can-low-level heap over-read in isotp-c","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.897+00:00","url":"https://junglewise.ai/threats/cve-2026-37532-automotive-grade-linux-agl-service-can-low-level-heap-over-read"},{"cve":"CVE-2026-37531","cvss":9.8,"epss":0.0014,"slug":"cve-2026-37531-automotive-grade-linux-app-framework-main-zip-slip-in-widget","title":"Automotive Grade Linux app-framework-main Zip Slip in widget installer","severity":"critical","exploited":false,"published_at":"2026-05-01T17:16:22.72+00:00","url":"https://junglewise.ai/threats/cve-2026-37531-automotive-grade-linux-app-framework-main-zip-slip-in-widget"},{"cve":"CVE-2026-37530","cvss":7.5,"epss":0.0002,"slug":"cve-2026-37530-automotive-grade-linux-agl-service-can-low-level-stack-overflow","title":"Automotive Grade Linux agl-service-can-low-level stack overflow in uds-c","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.603+00:00","url":"https://junglewise.ai/threats/cve-2026-37530-automotive-grade-linux-agl-service-can-low-level-stack-overflow"},{"cve":"CVE-2026-37526","cvss":7.8,"epss":0.0002,"slug":"cve-2026-37526-automotive-grade-linux-afb-daemon-improper-access-control-in","title":"Automotive Grade Linux afb-daemon improper access control in supervision socket","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.44+00:00","url":"https://junglewise.ai/threats/cve-2026-37526-automotive-grade-linux-afb-daemon-improper-access-control-in"},{"cve":"CVE-2026-37525","cvss":7.8,"epss":0.0001,"slug":"cve-2026-37525-automotive-grade-linux-afb-daemon-privilege-escalation-in","title":"Automotive Grade Linux afb-daemon privilege escalation in supervision Do command","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.27+00:00","url":"https://junglewise.ai/threats/cve-2026-37525-automotive-grade-linux-afb-daemon-privilege-escalation-in"},{"cve":"CVE-2026-40938","cvss":7.5,"epss":0.009,"slug":"cve-2026-40938-tekton-pipelines-argument-injection-in-git-resolver-revision","title":"Tekton Pipelines argument injection in Git resolver revision parameter","severity":"high","exploited":false,"published_at":"2026-04-21T21:16:46.283+00:00","url":"https://junglewise.ai/threats/cve-2026-40938-tekton-pipelines-argument-injection-in-git-resolver-revision"},{"cve":"CVE-2026-40924","cvss":6.5,"epss":0.0047,"slug":"cve-2026-40924-tekton-pipelines-dos-via-unbounded-memory-allocation-in-http","title":"Tekton Pipelines DoS via unbounded memory allocation in HTTP resolver","severity":"medium","exploited":false,"published_at":"2026-04-21T21:16:45.72+00:00","url":"https://junglewise.ai/threats/cve-2026-40924-tekton-pipelines-dos-via-unbounded-memory-allocation-in-http"},{"cve":"CVE-2026-40923","cvss":5.4,"epss":0.0032,"slug":"cve-2026-40923-tekton-pipelines-path-traversal-in-volumemount-validation","title":"Tekton Pipelines path traversal in VolumeMount validation","severity":"medium","exploited":false,"published_at":"2026-04-21T21:16:45.543+00:00","url":"https://junglewise.ai/threats/cve-2026-40923-tekton-pipelines-path-traversal-in-volumemount-validation"},{"cve":"CVE-2026-40161","cvss":7.7,"epss":0.0043,"slug":"cve-2026-40161-tekton-pipelines-credential-exfiltration-in-git-resolver-api-mode","title":"Tekton Pipelines credential exfiltration in Git resolver API mode","severity":"high","exploited":false,"published_at":"2026-04-21T17:16:53.79+00:00","url":"https://junglewise.ai/threats/cve-2026-40161-tekton-pipelines-credential-exfiltration-in-git-resolver-api-mode"},{"cve":"CVE-2026-25542","cvss":6.5,"epss":0.0039,"slug":"cve-2026-25542-tekton-pipelines-regex-bypass-in-trusted-resources-verification","title":"Tekton Pipelines regex bypass in trusted resources verification","severity":"medium","exploited":false,"published_at":"2026-04-21T17:16:24.213+00:00","url":"https://junglewise.ai/threats/cve-2026-25542-tekton-pipelines-regex-bypass-in-trusted-resources-verification"},{"cve":"CVE-2026-34045","cvss":8.2,"epss":0.0037,"slug":"cve-2026-34045-podman-desktop-dos-and-information-disclosure-in-webview-server","title":"Podman Desktop DoS and information disclosure in WebView server","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:17.557+00:00","url":"https://junglewise.ai/threats/cve-2026-34045-podman-desktop-dos-and-information-disclosure-in-webview-server"},{"cve":"CVE-2026-33701","cvss":9.8,"epss":0.0111,"slug":"cve-2026-33701-opentelemetry-java-instrumentation-rce-via-unsafe-deserialization","title":"OpenTelemetry Java Instrumentation RCE via Unsafe Deserialization in RMI","severity":"critical","exploited":false,"published_at":"2026-03-27T01:16:19.313+00:00","url":"https://junglewise.ai/threats/cve-2026-33701-opentelemetry-java-instrumentation-rce-via-unsafe-deserialization"},{"cve":"CVE-2026-29773","cvss":4.3,"epss":0.0032,"slug":"cve-2026-29773-kubewarden-incorrect-authorization-in-deprecated-host-callback","title":"Kubewarden incorrect authorization in deprecated host-callback APIs","severity":"medium","exploited":false,"published_at":"2026-03-10T17:39:03.21+00:00","url":"https://junglewise.ai/threats/cve-2026-29773-kubewarden-incorrect-authorization-in-deprecated-host-callback"},{"cve":"CVE-2026-29186","cvss":7.7,"epss":0.0091,"slug":"cve-2026-29186-backstage-techdocs-arbitrary-code-execution-via-mkdocs","title":"Backstage TechDocs arbitrary code execution via MkDocs configuration bypass","severity":"high","exploited":false,"published_at":"2026-03-07T15:15:55.4+00:00","url":"https://junglewise.ai/threats/cve-2026-29186-backstage-techdocs-arbitrary-code-execution-via-mkdocs"},{"cve":"CVE-2026-27134","cvss":8.1,"epss":0.0029,"slug":"cve-2026-27134-strimzi-kafka-operator-improper-authentication-in-mtls-ca-chain","title":"Strimzi Kafka Operator improper authentication in mTLS CA chain validation","severity":"high","exploited":false,"published_at":"2026-02-21T00:16:15.94+00:00","url":"https://junglewise.ai/threats/cve-2026-27134-strimzi-kafka-operator-improper-authentication-in-mtls-ca-chain"},{"cve":"CVE-2025-66623","cvss":7.4,"epss":0.0017,"slug":"cve-2025-66623-strimzi-provides-a-way-to-run-an-apache-kafka-cluster-on","title":"Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior","severity":"high","exploited":false,"published_at":"2025-12-05T19:15:52.91+00:00","url":"https://junglewise.ai/threats/cve-2025-66623-strimzi-provides-a-way-to-run-an-apache-kafka-cluster-on"}],"vendor":{"hub":true,"name":"Linuxfoundation","slug":"linuxfoundation","homepage":"https://www.linuxfoundation.org/","description":"A non-profit organization that provides a neutral home for open source projects and collaboration.","url":"https://junglewise.ai/threats/vendors/linuxfoundation"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-33701","cvss":9.8,"epss":0.0111,"slug":"cve-2026-33701-opentelemetry-java-instrumentation-rce-via-unsafe-deserialization","title":"OpenTelemetry Java Instrumentation RCE via Unsafe Deserialization in RMI","severity":"critical","exploited":false,"published_at":"2026-03-27T01:16:19.313+00:00","url":"https://junglewise.ai/threats/cve-2026-33701-opentelemetry-java-instrumentation-rce-via-unsafe-deserialization"},{"cve":"CVE-2026-37531","cvss":9.8,"epss":0.0014,"slug":"cve-2026-37531-automotive-grade-linux-app-framework-main-zip-slip-in-widget","title":"Automotive Grade Linux app-framework-main Zip Slip in widget installer","severity":"critical","exploited":false,"published_at":"2026-05-01T17:16:22.72+00:00","url":"https://junglewise.ai/threats/cve-2026-37531-automotive-grade-linux-app-framework-main-zip-slip-in-widget"},{"cve":"CVE-2026-34045","cvss":8.2,"epss":0.0037,"slug":"cve-2026-34045-podman-desktop-dos-and-information-disclosure-in-webview-server","title":"Podman Desktop DoS and information disclosure in WebView server","severity":"high","exploited":false,"published_at":"2026-04-07T21:17:17.557+00:00","url":"https://junglewise.ai/threats/cve-2026-34045-podman-desktop-dos-and-information-disclosure-in-webview-server"},{"cve":"CVE-2026-27134","cvss":8.1,"epss":0.0029,"slug":"cve-2026-27134-strimzi-kafka-operator-improper-authentication-in-mtls-ca-chain","title":"Strimzi Kafka Operator improper authentication in mTLS CA chain validation","severity":"high","exploited":false,"published_at":"2026-02-21T00:16:15.94+00:00","url":"https://junglewise.ai/threats/cve-2026-27134-strimzi-kafka-operator-improper-authentication-in-mtls-ca-chain"},{"cve":"CVE-2026-37526","cvss":7.8,"epss":0.0002,"slug":"cve-2026-37526-automotive-grade-linux-afb-daemon-improper-access-control-in","title":"Automotive Grade Linux afb-daemon improper access control in supervision socket","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.44+00:00","url":"https://junglewise.ai/threats/cve-2026-37526-automotive-grade-linux-afb-daemon-improper-access-control-in"},{"cve":"CVE-2026-37525","cvss":7.8,"epss":0.0001,"slug":"cve-2026-37525-automotive-grade-linux-afb-daemon-privilege-escalation-in","title":"Automotive Grade Linux afb-daemon privilege escalation in supervision Do command","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.27+00:00","url":"https://junglewise.ai/threats/cve-2026-37525-automotive-grade-linux-afb-daemon-privilege-escalation-in"},{"cve":"CVE-2026-29186","cvss":7.7,"epss":0.0091,"slug":"cve-2026-29186-backstage-techdocs-arbitrary-code-execution-via-mkdocs","title":"Backstage TechDocs arbitrary code execution via MkDocs configuration bypass","severity":"high","exploited":false,"published_at":"2026-03-07T15:15:55.4+00:00","url":"https://junglewise.ai/threats/cve-2026-29186-backstage-techdocs-arbitrary-code-execution-via-mkdocs"},{"cve":"CVE-2026-40161","cvss":7.7,"epss":0.0043,"slug":"cve-2026-40161-tekton-pipelines-credential-exfiltration-in-git-resolver-api-mode","title":"Tekton Pipelines credential exfiltration in Git resolver API mode","severity":"high","exploited":false,"published_at":"2026-04-21T17:16:53.79+00:00","url":"https://junglewise.ai/threats/cve-2026-40161-tekton-pipelines-credential-exfiltration-in-git-resolver-api-mode"},{"cve":"CVE-2026-40938","cvss":7.5,"epss":0.009,"slug":"cve-2026-40938-tekton-pipelines-argument-injection-in-git-resolver-revision","title":"Tekton Pipelines argument injection in Git resolver revision parameter","severity":"high","exploited":false,"published_at":"2026-04-21T21:16:46.283+00:00","url":"https://junglewise.ai/threats/cve-2026-40938-tekton-pipelines-argument-injection-in-git-resolver-revision"},{"cve":"CVE-2026-37530","cvss":7.5,"epss":0.0002,"slug":"cve-2026-37530-automotive-grade-linux-agl-service-can-low-level-stack-overflow","title":"Automotive Grade Linux agl-service-can-low-level stack overflow in uds-c","severity":"high","exploited":false,"published_at":"2026-05-01T17:16:22.603+00:00","url":"https://junglewise.ai/threats/cve-2026-37530-automotive-grade-linux-agl-service-can-low-level-stack-overflow"}],"generated_at":"2026-09-26T16:07:00.132667+00:00","technologies":[{"name":"Linuxfoundation Automotive Grade Linux","slug":"automotive-grade-linux","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/automotive-grade-linux"},{"name":"Linuxfoundation Tekton Pipelines","slug":"tekton-pipelines","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/tekton-pipelines"}]}