CVSS: 9.4EPSS: 0%CPEs: 1EXPL: 0CVE-2026-25848
https://notcve.org/view.php?id=CVE-2026-25848
09 Feb 2026 — In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-306: Missing Authentication for Critical Function •
CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0CVE-2025-64683
https://notcve.org/view.php?id=CVE-2025-64683
10 Nov 2025 — In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVSS: 3.3EPSS: 0%CPEs: 1EXPL: 0CVE-2025-64682
https://notcve.org/view.php?id=CVE-2025-64682
10 Nov 2025 — In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVSS: 3.3EPSS: 0%CPEs: 1EXPL: 0CVE-2025-64681
https://notcve.org/view.php?id=CVE-2025-64681
10 Nov 2025 — In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-862: Missing Authorization •
CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 0CVE-2025-24456
https://notcve.org/view.php?id=CVE-2025-24456
21 Jan 2025 — In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-288: Authentication Bypass Using an Alternate Path or Channel •
CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0CVE-2024-50573
https://notcve.org/view.php?id=CVE-2024-50573
28 Oct 2024 — In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-862: Missing Authorization •
CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0CVE-2024-38507
https://notcve.org/view.php?id=CVE-2024-38507
18 Jun 2024 — In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible En JetBrains Hub antes de 2024.2.34646 era posible XSS Almacenado a través de la descripción del proyecto • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0CVE-2023-45823 – Arbitrary file read in Artifact Hub
https://notcve.org/view.php?id=CVE-2023-45823
19 Oct 2023 — Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which by using symbolic links in certain kinds of repositories loaded into Artifact Hub, it was possible to read internal files. Artifact Hub indexes content from a variety of sources, including git repositories. When processing git based repositories, Artifact Hub clones the repos... • https://artifacthub.io/packages/helm/artifact-hub/artifact-hub?modal=changelog&version=1.16.0 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0CVE-2023-45822 – Unsafe rego built-in allowed in Artifact Hub
https://notcve.org/view.php?id=CVE-2023-45822
19 Oct 2023 — Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which a default unsafe rego built-in was allowed to be used when defining authorization policies. Artifact Hub includes a fine-grained authorization mechanism that allows organizations to define what actions can be performed by their members. It is based on customizable authorizati... • https://artifacthub.io/packages/helm/artifact-hub/artifact-hub?modal=changelog&version=1.16.0 • CWE-918: Server-Side Request Forgery (SSRF) •
CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0CVE-2023-45821 – Incorrect Docker Hub registry check in Artifact Hub
https://notcve.org/view.php?id=CVE-2023-45821
19 Oct 2023 — Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which the `registryIsDockerHub` function was only checking that the registry domain had the `docker.io` suffix. Artifact Hub allows providing some Docker credentials that are used to increase the rate limit applied when interacting with the Docker Hub registry API to read publicly ... • https://artifacthub.io/packages/helm/artifact-hub/artifact-hub?modal=changelog&version=1.16.0 • CWE-494: Download of Code Without Integrity Check •
