CVE-2017-1000001: Fedoraproject Fedmsg

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.

Affected products

Published 2017-07-17. Last modified 2026-06-17.