github.com/runatlantis/atlantis
Terraform Pull Request Automation
Activity
- Latest release
- 3w ago
- Total releases
- 55
- Cadence
- ~2 months
- Last 12 months
- 14
Reach
- Stars
- 9.3k
Details
- First release
- Aug 17, 2017
| Version | Released | |
|---|---|---|
v0.47.1
patch
1 CVE
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.47.1
patch
Dependencies (59)
+ 51 more |
|
v0.47.0
minor
1 CVE
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.47.0
minor
Dependencies (59)
+ 51 more |
|
v0.46.0
minor
1 CVE
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.46.0
minor
Dependencies (54)
+ 46 more |
|
v0.45.0
minor
1 CVE
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.45.0
minor
Dependencies (54)
+ 46 more |
|
v0.44.1
patch
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.44.1
patch
Dependencies (52)
+ 44 more |
|
v0.44.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.44.0
minor
Dependencies (52)
+ 44 more |
|
v0.43.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.43.0
minor
Dependencies (52)
+ 44 more |
|
v0.42.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.42.0
minor
Dependencies (52)
+ 44 more |
|
v0.41.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.41.0
minor
Dependencies (52)
+ 44 more |
|
v0.40.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.40.0
minor
Dependencies (51)
+ 43 more |
|
v0.39.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.39.0
minor
Dependencies (50)
+ 42 more |
|
v0.38.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.38.0
minor
Dependencies (51)
+ 43 more |
|
v0.37.1
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.37.1
minor
Dependencies (51)
+ 43 more |
|
v0.37.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.37.0
minor
Dependencies (51)
+ 43 more |
|
v0.36.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.36.0
minor
Dependencies (51)
+ 43 more |
|
v0.35.1
patch
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.35.1
patch
Dependencies (51)
+ 43 more |
|
v0.35.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (51)
+ 43 more |
|
v0.34.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.34.0
minor
Dependencies (51)
+ 43 more |
|
v0.33.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.33.0
minor
Dependencies (51)
+ 43 more |
|
v0.32.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (50)
+ 42 more |
|
v0.31.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.31.0
minor
Dependencies (50)
+ 42 more |
|
v0.30.0
minor
2 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (50)
+ 42 more |
|
v0.29.0
minor
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.29.0
minor
Dependencies (49)
+ 41 more |
|
v0.28.5
patch
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.28.5
patch
Dependencies (49)
+ 41 more |
|
v0.28.3
patch
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.28.3
patch
Dependencies (49)
+ 41 more |
|
v0.28.2
patch
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.28.2
patch
Dependencies (49)
+ 41 more |
|
v0.28.0
minor
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.28.0
minor
Dependencies (49)
+ 41 more |
|
v0.24.4
patch
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.24.4
patch
Dependencies (47)
+ 39 more |
|
v0.24.2
minor
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.24.2
minor
Dependencies (47)
+ 39 more |
|
v0.22.3
patch
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.22.3
patch
Dependencies (46)
+ 38 more |
|
v0.22.2
minor
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.22.2
minor
Dependencies (46)
+ 38 more |
|
v0.19.9
patch
3 CVEs
CVE-2026-64679
GO-2026-6273
GHSA-26w5-6g95-gj28
Aug 25, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis Fixed in
0.45.0
References Updated Aug 25, 2026 · Source: OSV.dev
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev |
v0.19.9
patch
Dependencies (44)
+ 36 more |
|
v0.19.4
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.19.4
patch
Dependencies (43)
+ 35 more |
|
v0.19.2
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.19.2
minor
Dependencies (40)
+ 32 more |
|
v0.18.3
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.18.3
minor
Dependencies (40)
+ 32 more |
|
v0.17.6
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.17.6
patch
Dependencies (38)
+ 30 more |
|
v0.17.2
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.17.2
patch
Dependencies (38)
+ 30 more |
|
v0.17.0
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (38)
+ 30 more |
|
v0.17.0-beta
pre
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.17.0-beta
pre
Dependencies (36)
+ 28 more |
|
v0.16.1
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.16.1
patch
Dependencies (36)
+ 28 more |
|
v0.16.0
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (36)
+ 28 more |
|
v0.15.1
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.15.1
minor
Dependencies (36)
+ 28 more |
|
v0.13.0
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (34)
+ 26 more |
|
v0.11.1
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.11.1
minor
Dependencies (31)
+ 23 more |
|
v0.8.2
minor
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.8.2
minor
|
|
v0.7.0-alpha1
pre
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.7.0-alpha1
pre
|
|
v0.4.12
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.12
patch
|
|
v0.4.11
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.11
patch
|
|
v0.4.8
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.8
patch
|
|
v0.4.7
patch
3 CVEs
CVE-2025-58445
GO-2025-3940
GHSA-xh7v-965r-23f7
Sep 17, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Atlantis Exposes Service Version Publicly on /status API Endpoint in github.com/runatlantis/atlantis Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-52009
GO-2024-3265
GHSA-gppm-hq3p-h4rp
Nov 20, 2024
Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis Fixed in
0.30.0
References
Updated Dec 12, 2024 · Source: OSV.dev
CVE-2022-24912
GO-2022-0534
GHSA-jxqv-jcvh-7gr4
Aug 11, 2022
Timing attack in github.com/runatlantis/atlantis Validation of Gitlab requests can leak secrets. The package github.com/runatlantis/atlantis/server/controllers/events uses a non-constant time comparison for secrets while validating a Gitlab request. This allows for a timing attack where an attacker can recover a secret and then forge the request. Fixed in
0.19.7
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.4.7
patch
|