Security: mindersec/minder
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Minder does not sandbox http.send in Rego programsGHSA-6xvf-4vh9-mw47 published
Nov 20, 2025 by evankandersonHigh -
Denial of service from maliciously configured Git repositoryGHSA-hpcg-xjq5-g666 published
Jun 18, 2024 by JAORMXModerate -
Denial of service from maliciously crafted templatesGHSA-crgc-2583-rw27 published
May 20, 2024 by JAORMXModerate -
Denial of service of Minder Server with attacker-controlled REST endpointGHSA-fjw8-3gp8-4cvx published
May 16, 2024 by JAORMXModerate -
Denial of service of Minder Server from maliciously crafted GitHub attestationsGHSA-8fmj-33gw-g7pw published
May 27, 2024 by JAORMXModerate -
Github Webhook Handler vulnerable to DoS from un-validated requestsGHSA-9c5w-9q3f-3hv7 published
May 7, 2024 by JAORMXHigh -
GetRepositoryByName data leakGHSA-ggp5-28x4-xcj9 published
Apr 9, 2024 by JAORMXModerate -
`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any authenticated userGHSA-v627-69v2-xx37 published
Mar 4, 2024 by JAORMXHigh -
Minder trusts client-provided mapping from repo name to upstream IDGHSA-q6h8-4j2v-pjg4 published
Feb 26, 2024 by evankandersonModerate