CVE-2017-1000001: Fedoraproject Fedmsg
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
Affected products
- Fedoraproject Fedmsg: up to and including 0.18.1
Published 2017-07-17. Last modified 2026-06-17.