cbcvebase.

Aws Loom vulnerabilities

3 known vulnerabilities affecting aws/loom.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-103956P2CRITICALCVSS 10.0fixed in 1.6.12026-10-02
CVE-2026-103956 [CRITICAL] CWE-306 CVE-2026-103956: Missing authentication for critical function in the authentication dependency in Loom for AWS before Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any req
nvd
CVE-2026-103958P3HIGHCVSS 7.6fixed in 1.7.02026-10-02
CVE-2026-103958 [HIGH] CWE-918 CVE-2026-103958: Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updatin
nvd
CVE-2026-103957P3MEDIUMCVSS 6.2fixed in 1.7.02026-10-02
CVE-2026-103957 [MEDIUM] CWE-201 CVE-2026-103957: Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allo Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a
nvd
Aws Loom vulnerabilities | cvebase