Known vulnerabilities in flatpak (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:flatpak_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 10
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting flatpak (Debian package) flatpak (Debian package) is affected by 10 known vulnerabilities: 1 high, 3 medium, 6 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125296 - Improper Access Control
CVE-2026-34078
CWE-284 High
No
No
1.14.10-1~deb12u2, 1.16.6-1~deb13u1 08.04.2026 SB2026040858
SB2026040865
SB2026040866
and 28 more
#VU125295 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-34079
CWE-22 Low
No
No
1.14.10-1~deb12u2, 1.16.6-1~deb13u1 08.04.2026 SB2026040858
SB2026040865
SB2026040866
and 28 more
#VU96049 - UNIX Symbolic Link (Symlink) Following
CVE-2024-42472
CWE-61 Low
No
No
1.14.10-1~deb12u1 15.08.2024 SB2024081541
SB2024081542
SB2024081553
and 29 more
#VU88827 - Argument Injection or Modification
CVE-2024-32462
CWE-88 Low
No
No
1.10.8-0+deb11u2, 1.14.4-1+deb12u1 19.04.2024 SB2024041902
SB2024041903
SB2024042944
and 29 more
#VU59689 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-21682
CWE-22 Medium
No
No
1.10.7-0+deb11u1 18.01.2022 SB2022011811
SB2022012525
SB2022110837
and 8 more
#VU59654 - Permissions, Privileges, and Access Controls
CVE-2021-43860
CWE-264 Medium
No
No
1.10.7-0+deb11u1 17.01.2022 SB2022011715
SB2022012525
SB2022051141
and 8 more
#VU57176 - Permissions, Privileges, and Access Controls
CVE-2021-41133
CWE-264 Low
No
No
1.10.5-0+deb11u1 08.10.2021 SB2021100815
SB2021101417
SB2021110212
and 17 more
#VU51443 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-21381
CWE-74 Medium
No
No
1.2.5-0+deb10u4 14.03.2021 SB2021031112
SB2021031403
SB2021031408
and 11 more
#VU49587 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-21261
CWE-94 Low
No
No
1.2.5-0+deb10u2 14.01.2021 SB2021011821
SB2021011822
SB2021012105
and 12 more
#VU17726 - Permissions, Privileges, and Access Controls
CVE-2019-8308
CWE-264 Low
No
No
0.8.9-0+deb9u2 16.02.2019 SB2019021601
SB2019021813
SB2019021924
and 5 more