CVE-2018-1277: Cloudfoundry Cf-Deployment

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.

Affected products

Published 2018-04-30. Last modified 2026-06-17.