CVE-2022-2074: Octopus Server

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

Affected products

  • Octopus Octopus Server: from 0.9, up to and including 0.9.620.4; from 1.0, up to and including 1.6.3.1723; from 2.0, up to and including 2.6.5; from 3.0.0, up to and including 3.17.14; from 4.0.4, up to and including 4.1.10; from 2018.1.0, up to and including 2018.12.1; …

Published 2022-08-19. Last modified 2026-06-17.