Vulnerability disclosures and security advisories
| ID | Summary | Severity | Date |
|---|---|---|---|
| GHSA-5fx4-c9qp-36jc | Unauthenticated S3 gRPC identity management enables IAM admin access | Critical | Sep 18, 2026 |
| GHSA-jw56-gm6j-34mp | Broad-policy S3 identities can escalate to IAM admin | Critical | Sep 2, 2026 |
| CVE-2026-17615 | Unauthenticated file read through the Resteasy sourceprovider | High (7.5) | Aug 31, 2026 |
| CVE-2026-49086 | Dapr Pub/Sub headers can influence internal routing | Medium (6.5) | Jul 6, 2026 |