Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CycloneDX — Vulnerabilities & Security Advisories 4

Browse all 4 CVE security advisories affecting CycloneDX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CycloneDX serves as an open standard for software bill of materials (SBOM) generation, enabling organizations to inventory and manage components in their software supply chain. Historically, vulnerabilities in CycloneDX implementations have included cross-site scripting (XSS), remote code execution (RCE), and privilege escalation flaws, often stemming from improper input validation or insecure deserialization. While no major security incidents have been widely reported, the presence of four CVEs highlights potential risks in SBOM processing tools. The project's security posture emphasizes transparency through vulnerability disclosure, though adoption of secure coding practices remains critical as SBOM usage grows in software ecosystems.

Found 2 results / 4Clear Filters

This page lists every published CVE security advisory associated with CycloneDX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.