CVE-2022-27892: Palantir Gotham

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service.

Affected products

  • Palantir Gotham: before 3.22.11.2 (fixed in 3.22.11.2)

Published 2023-02-16. Last modified 2026-06-17.