github.com/treeverse/lakefs
lakeFS - Data version control for your data lake | Git for data
Activity
- Latest release
- 1mo ago
- Total releases
- 67
- Cadence
- ~22 days
- Last 12 months
- 20
Reach
- Stars
- 5.5k
Details
- First release
- Aug 06, 2020
| Version | Released | |
|---|---|---|
v1.86.0
minor
|
v1.86.0
minor
Dependencies (94)
+ 86 more |
|
v1.85.0
minor
|
v1.85.0
minor
Dependencies (94)
+ 86 more |
|
v1.84.1
patch
|
v1.84.1
patch
Dependencies (94)
+ 86 more |
|
v1.84.0
minor
|
v1.84.0
minor
Dependencies (94)
+ 86 more |
|
v1.83.0
minor
|
v1.83.0
minor
Dependencies (94)
+ 86 more |
|
v1.82.0
minor
|
v1.82.0
minor
Dependencies (94)
+ 86 more |
|
v1.81.1
patch
|
v1.81.1
patch
Dependencies (95)
+ 87 more |
|
v1.81.0
minor
|
v1.81.0
minor
Dependencies (95)
+ 87 more |
|
v1.80.0
minor
|
v1.80.0
minor
Dependencies (105)
+ 97 more |
|
v1.79.0
minor
|
v1.79.0
minor
Dependencies (94)
+ 86 more |
|
v1.78.0
minor
|
v1.78.0
minor
Dependencies (94)
+ 86 more |
|
v1.77.1
patch
|
v1.77.1
patch
Dependencies (94)
+ 86 more |
|
v1.77.0
minor
|
v1.77.0
minor
Dependencies (95)
+ 87 more |
|
v1.76.0
minor
1 CVE
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev |
v1.76.0
minor
Dependencies (95)
+ 87 more |
|
v1.75.0
minor
1 CVE
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev |
v1.75.0
minor
Dependencies (95)
+ 87 more |
|
v1.74.4
minor
2 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.74.4
minor
Dependencies (95)
+ 87 more |
|
v1.74.3
patch
2 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.74.3
patch
Dependencies (95)
+ 87 more |
|
v1.74.2
patch
2 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.74.2
patch
Dependencies (95)
+ 87 more |
|
v1.74.1
patch
2 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.74.1
patch
Dependencies (95)
+ 87 more |
|
v1.74.0
minor
2 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.74.0
minor
Dependencies (95)
+ 87 more |
|
v1.70.0
minor
3 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.70.0
minor
Dependencies (91)
+ 83 more |
|
v1.60.0
minor
3 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.60.0
minor
Dependencies (93)
+ 85 more |
|
v1.57.0
minor
3 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.57.0
minor
Dependencies (94)
+ 86 more |
|
v1.54.0
minor
3 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.54.0
minor
Dependencies (92)
+ 84 more |
|
v1.49.0
minor
4 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.49.0
minor
Dependencies (91)
+ 83 more |
|
v1.41.0
minor
4 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.41.0
minor
Dependencies (91)
+ 83 more |
|
v1.29.0
minor
5 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.29.0
minor
Dependencies (91)
+ 83 more |
|
v1.26.0
minor
5 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.26.0
minor
Dependencies (87)
+ 79 more |
|
v1.23.0
minor
5 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.23.0
minor
Dependencies (87)
+ 79 more |
|
v1.16.0
minor
5 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (87)
+ 79 more |
|
v1.15.0
minor
5 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (87)
+ 79 more |
|
v1.13.0
minor
5 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.13.0
minor
Dependencies (87)
+ 79 more |
|
v1.11.1
minor
6 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.11.1
minor
Dependencies (87)
+ 79 more |
|
v1.1.0
major
7 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
major
Dependencies (91)
+ 83 more |
|
v0.107.0
minor
7 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.107.0
minor
Dependencies (85)
+ 77 more |
|
v0.106.2
minor
7 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.106.2
minor
Dependencies (85)
+ 77 more |
|
v0.102.2
minor
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.102.2
minor
Dependencies (84)
+ 76 more |
|
v0.101.0
minor
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.101.0
minor
Dependencies (84)
+ 76 more |
|
v0.101.1
patch
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.101.1
patch
Dependencies (84)
+ 76 more |
|
v0.99.1
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.99.1
minor
Dependencies (83)
+ 75 more |
|
v0.98.0
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.98.0
minor
Dependencies (83)
+ 75 more |
|
v0.97.6
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.97.6
minor
Dependencies (81)
+ 73 more |
|
v0.95.0
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.95.0
minor
Dependencies (80)
+ 72 more |
|
v0.93.0
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.93.0
minor
Dependencies (82)
+ 74 more |
|
v0.91.0
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2581
GHSA-fvv5-h29g-f6w5
Jun 04, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository in github.com/treeverse/lakefs Fixed in
1.12.1
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.91.0
minor
Dependencies (78)
+ 70 more |
|
v0.88.0
minor
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.88.0
minor
Dependencies (76)
+ 68 more |
|
v0.87.1
minor
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.87.1
minor
Dependencies (76)
+ 68 more |
|
v0.85.0
minor
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.85.0
minor
Dependencies (74)
+ 66 more |
|
v0.83.4
minor
8 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.83.4
minor
Dependencies (74)
+ 66 more |
|
v0.70.2
minor
9 CVEs
CVE-2026-26187
GO-2026-4494
GHSA-699m-4v95-rmpm
Feb 17, 2026
lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access in github.com/treeverse/lakefs Fixed in
1.77.0
References Updated Feb 19, 2026 · Source: OSV.dev
CVE-2025-68671
GO-2026-4321
GHSA-f2ph-gc9m-q55f
Jan 23, 2026
lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs lakeFS is Missing Timestamp Validation in S3 Gateway Authentication in github.com/treeverse/lakefs Fixed in
1.75.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-64179
GO-2025-4090
GHSA-h238-5mwf-8xw8
Nov 17, 2025
lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs lakeFS affected by unauthenticated access to API usage metrics in github.com/treeverse/lakefs Fixed in
1.71.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-27100
GO-2025-3479
GHSA-j7jw-28jm-whr6
Mar 03, 2025
lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs lakeFS allows an authenticated user to cause a crash by exhausting server memory in github.com/treeverse/lakefs Fixed in
1.50.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-43784
GO-2024-3291
GHSA-hh33-46q4-hwm2
Nov 27, 2024
Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion in github.com/treeverse/lakefs Fixed in
1.33.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-1019
GHSA-28q9-9c3g-v3f9
Aug 21, 2024
lakeFS vulnerable to authenticated users deleting files they are not authorized to delete in github.com/treeverse/lakefs lakeFS vulnerable to authenticated users deleting files they are not authorized to delete in github.com/treeverse/lakefs Fixed in
0.82.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2397
GHSA-26hr-q2wp-rvc5
Aug 21, 2024
User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs User with permission to write actions can impersonate another user when auth token is configured in environment variable in github.com/treeverse/lakefs Fixed in
1.3.1
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2398
GHSA-4rgc-5g6r-2rjf
Aug 21, 2024
lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs lakeFS logs S3 credentials in plain text in github.com/treeverse/lakefs Fixed in
0.101.0
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-2012
GHSA-9phh-r37v-34wh
Aug 21, 2024
lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs lakeFS vulnerable to Arbitrary JavaScript Injection via Direct Link to HTML Files in github.com/treeverse/lakefs Fixed in
0.106.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.70.2
minor
Dependencies (78)
+ 70 more |