github.com/treeverse/lakefs
Go5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/treeverse/lakefspage 1 of 1
- CVE-2024-43784MEDIUMCVSS 5.7EG 5.7✓ Fixed in 1.33.02024-11-26
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the…
- CVE-2025-27100MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.50.02025-02-21
lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue. This …
- CVE-2025-64179MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.71.02025-11-06
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below, missing authentication in the /api/v1/usage-report/summary endpoint allows anyone to retrieve aggregate API usage coun…
- CVE-2025-68671MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.75.02026-01-15
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a val…
- CVE-2026-26187HIGHCVSS 8.1EG 8.1✓ Fixed in 1.77.02026-02-13
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated st…
Check whether github.com/treeverse/lakefs is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/treeverse/lakefs CVEs against the assets you own.
Start Free Scan →