Vulnerabilities

Last updated 19 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/stacklok/toolhive ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement High Risk 8.8 10 days ago 3 hours ago
github.com/stacklok/toolhive ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement in github.com/stacklok/toolhive Unknown 4 hours ago 4 hours ago
github.com/stacklok/toolhive ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway Low Risk 3.0 2 months ago 2 months ago
github.com/stacklok/toolhive ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) Medium Risk 4.7 2 months ago 2 months ago
github.com/stacklok/toolhive ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway in github.com/stacklok/toolhive Unknown 2 months ago 2 months ago
github.com/stacklok/toolhive ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) in github.com/stacklok/toolhive Unknown 2 months ago 2 months ago