Back to Guardra

CVEs coordinated by Guardra Labs.

Our research team has disclosed 40+ CVEs since 2023 across cloud infrastructure, identity systems, LLM tooling, and open-source dependencies. 90-day default disclosure window.

Recent disclosures

40+ since 2023
CVESeverityTitleVendorDate
CVE-2026-11284CRITICAL 9.8OAuth authentication bypassoauth-toolkitFeb 2026Details
CVE-2025-98712HIGH 8.6Prototype pollution in Top-50 npm package(coordinated)Dec 2025Details
CVE-2025-74419CRITICAL 9.1Deserialization RCE in CI plugin(coordinated)Oct 2025Details
CVE-2025-51007HIGH 8.1LLM prompt-injection → data exfiltrationAI coding assistantJul 2025Details
CVE-2025-44910HIGH 7.8Indirect injection in major RAG framework(coordinated)Jun 2025Details
CVE-2025-30182CRITICAL 9.4Tool-call confused-deputy in agent SDK(coordinated)Apr 2025Details
CVE-2025-19847HIGH 8.3Vector-store authentication flawCloud vendorFeb 2025Details
CVE-2024-98221CRITICAL 9.9Memory exfiltration via chained tool-calls(coordinated)Dec 2024Details
CVE-2024-75591HIGH 8.0SSRF in webhook proxy serviceCI platformSep 2024Details
CVE-2024-43102MEDIUM 6.3IAM policy parser ambiguityCloud vendorJun 2024Details
CVE-2024-17810HIGH 8.4Secrets manager race on rotation(coordinated)Mar 2024Details
CVE-2023-92011CRITICAL 9.6Supply-chain substitution attack (dep confusion)(multiple)Nov 2023Details

Coordinated disclosure policy

Default 90-day window. Extended on request for vendors acting in good faith. If a vulnerability is being actively exploited, we reserve the right to publish sooner. All disclosures include a reproducer, impact analysis, and suggested mitigations.