Skip to content
English

Products › Server applications and development

Server applications and development

Development and CI/CD

Code forges, continuous integration pipelines, package repositories and developer tools.

For example: Jenkins, GitLab, TeamCity, JFrog Artifactory.

Category RSS feed

Pace of additions

Number of “Development and CI/CD” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20251
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20263
Feb 1, 2026 to Mar 2, 20263
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20261
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20263
Aug 30, 2026 to Sep 28, 2026 (in progress)4

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Aqua Security 1 vulnerability · 1 in the last 12 months
  • Atlassian 1 vulnerability
  • Docker 1 vulnerability
  • Git 1 vulnerability
  • Gitea 1 vulnerability · 1 in the last 12 months
  • GitLab 5 vulnerabilities · 3 in the last 12 months
  • Gogs 1 vulnerability · 1 in the last 12 months
  • Jenkins 6 vulnerabilities · 1 in the last 12 months
  • JetBrains 4 vulnerabilities · 2 in the last 12 months
  • JFrog 4 vulnerabilities · 4 in the last 12 months
  • Nx 1 vulnerability · 1 in the last 12 months
  • PHPUnit 1 vulnerability
  • Prettier 1 vulnerability · 1 in the last 12 months
  • React Native Community 1 vulnerability · 1 in the last 12 months
  • reviewdog 1 vulnerability
  • Sonatype 2 vulnerabilities
  • tj-actions 1 vulnerability
  • Vite 1 vulnerability · 1 in the last 12 months

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1GitLab Community / Enterprise Edition (CE/EE)

    CVE-2026-85706

    Recently addedHunt for compromise (CISA)

    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2JFrog Artifactory

    CVE-2026-42016

    Recently added

    JFrog Artifactory Incorrect Authorization Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  3. Rank 3JFrog Artifactory

    CVE-2026-42018

    Recently added

    JFrog Artifactory Improper Authentication Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 11, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  4. Rank 4JFrog Artifactory

    CVE-2026-82329

    Recently addedHunt for compromise (CISA)

    JFrog Artifactory Improper Authentication Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 2, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Gitea

    CVE-2026-60004

    Hunt for compromise (CISA)

    Gitea Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 25, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  6. Rank 6JetBrains TeamCity

    CVE-2026-63077

    Hunt for compromise (CISA)Ransomware

    JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 5, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Nx Console

    CVE-2026-48027

    Ransomware

    Nx Console Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 27, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  8. Rank 8GitLab Community / Enterprise Edition (CE/EE)

    CVE-2021-22175

    CVE from 2021, added in 2026

    GitLab Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 18, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9React Native Community React Native CLI

    CVE-2025-11953

    React Native Community CLI OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Jenkins Core

    CVE-2017-1000353

    CVE from 2017, added in 2025

    Jenkins Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 24 more vulnerabilities
  1. Rank 11Aqua Security Trivy

    CVE-2026-33634

    Aquasecurity Trivy Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 26, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  2. Rank 12Gogs

    CVE-2025-8110

    Gogs Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 12, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Rank 13GitLab Community / Enterprise Edition (CE/EE)

    CVE-2021-39935

    CVE from 2021, added in 2026

    GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 3, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  4. Rank 14Vite

    CVE-2025-31125

    Vite Vitejs Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  5. Rank 15Prettier eslint-config-prettier

    CVE-2025-54313

    Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 22, 2026
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  6. Rank 16JetBrains TeamCity

    CVE-2024-27199

    RansomwareCVE from 2024, added in 2026

    JetBrains TeamCity Relative Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.3 (high)
  7. Rank 17JFrog Artifactory

    CVE-2026-66384

    JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 27, 2026
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  8. Rank 18GitLab Community / Enterprise Edition (CE/EE)

    CVE-2021-22205

    Ransomware

    GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    10.0 (critical)
  9. Rank 19Jenkins Plugins

    CVE-2019-1003029

    CVE from 2019, added in 2022

    Jenkins Script Security Plugin Sandbox Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  10. Rank 20Jenkins Plugins

    CVE-2019-1003030

    CVE from 2019, added in 2022

    Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.9 (critical)
  11. Rank 21Jenkins Core

    CVE-2024-23897

    Ransomware

    Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 19, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22GitLab Community / Enterprise Edition (CE/EE)

    CVE-2023-7028

    GitLab Community and Enterprise Editions Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23JetBrains TeamCity

    CVE-2024-27198

    Ransomware

    JetBrains TeamCity Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24JetBrains TeamCity

    CVE-2023-42793

    Ransomware

    JetBrains TeamCity Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 4, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25PHPUnit

    CVE-2017-9841

    CVE from 2017, added in 2022

    PHPUnit Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Jenkins Core

    CVE-2018-1000861

    CVE from 2018, added in 2022

    Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Sonatype Nexus Repository

    CVE-2019-7238

    CVE from 2019, added in 2021

    Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Atlassian Bitbucket Server / Data Center

    CVE-2022-36804

    Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  19. Rank 29Sonatype Nexus Repository

    CVE-2020-10199

    Sonatype Nexus Repository Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  20. Rank 30reviewdog action-setup GitHub Action

    CVE-2025-30154

    reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 24, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  21. Rank 31tj-actions changed-files GitHub Action

    CVE-2025-30066

    tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 18, 2025
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  22. Rank 32Git

    CVE-2025-48384

    Git Link Following Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2025
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  23. Rank 33Docker Desktop

    CVE-2019-15752

    CVE from 2019, added in 2021

    Docker Desktop Community Edition Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  24. Rank 34Jenkins Core

    CVE-2015-5317

    CVE from 2015, added in 2023

    Jenkins User Interface (UI) Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 12, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.