CVE security advisories and vulnerability history for salt by saltstack.
53
Total CVEs
Published
3
In CISA KEV
Exploited in the wild
7
Public exploits
With known exploit
7.9
Avg CVSS
2013–2025
Last updated
Overview
saltstack salt has 53 published CVE records since 2013, of which 3 are in CISA's Known Exploited Vulnerabilities catalog and 7 have a known public exploit. The average CVSS base score across scored CVEs is 7.9.
This page aggregates every publicly disclosed vulnerability (CVE) affecting saltstack salt, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of saltstack salt's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical5
High5
Medium2
Low1
40 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
3
3 of saltstack salt's CVEs are confirmed exploited in the wild.
Public exploits
7
7 of saltstack salt's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every saltstack salt version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about saltstack salt vulnerabilities.
How many CVEs does saltstack salt have?
saltstack salt has 53 published CVE records since 2013.
How many saltstack salt CVEs are in CISA KEV?
Yes — 3 of saltstack salt's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for saltstack salt vulnerabilities?
Yes — 7 of saltstack salt's CVEs have a known public exploit.
Which versions of saltstack salt are affected?
228 distinct saltstack salt versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in saltstack salt CVEs?
saltstack salt's CVEs most often map to these CWE weakness types: CWE-287 (Improper Authentication), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-295 (Improper Certificate Validation), CWE-732 (Incorrect Permission Assignment for Critical Resource).
How many critical saltstack salt vulnerabilities are there?
saltstack salt has 5 critical and 5 high-severity CVEs.
What is the average severity of saltstack salt CVEs?
The average CVSS base score across saltstack salt's scored CVEs is 7.9.