Skip to main content

Vendor/product archive

lfprojects / zarf CVEs

Beta · best-effort

2 CVEs tagged to lfprojects / zarf0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-40090

Published Apr 15, 2026

Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf package inspect sbom and zarf pa…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-29064

Published Mar 6, 2026

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically…

CVSS 8.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1