gocd

10 known vulnerabilities in gocd, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-55632 CVSS 4.3 medium GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing…
  • CVE-2026-52744 CVSS 5.3 medium GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at…
  • CVE-2026-68919 CVSS 7.0 high GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification…
  • CVE-2026-55870 CVSS 2.3 low GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo…
  • CVE-2026-55625 CVSS 4.9 medium GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at…
  • CVE-2026-55060 CVSS 3.7 low GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended…
  • CVE-2026-52743 CVSS 4.3 medium GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested…
  • CVE-2026-52742 CVSS 5.1 medium GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server…
  • CVE-2026-52741 CVSS 7.5 high GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a…
  • CVE-2026-52740 CVSS 5.3 medium GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively…