Dapr Linux Foundation Dapr

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Linux Foundation Dapr.

By the Year

In 2026 there have been 1 vulnerability in Linux Foundation Dapr with an average score of 7.5 out of ten. Dapr did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 7.50
2025 0 0.00
2024 0 0.00
2023 1 7.50

It may take a day or so for new Dapr vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Linux Foundation Dapr Security Vulnerabilities

Dapr Sentry OIDC Discovery Host Header Injection (1.17-1.18)
CVE-2026-59096 7.5 - High - July 02, 2026

Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts list is configured (the default), and serves the document with a one-hour public cache lifetime. A remote unauthenticated attacker can poison the discovery document so relying parties performing dynamic (unpinned) discovery fetch the JWKS from an attacker-controlled server, causing attacker-signed JWTs to be accepted. Exploitation requires the OIDC server enabled without a configured jwt-issuer or oidc-allowed-hosts.

Origin Validation Error

Dapr API Token Auth Bypass (pre-1.10.9/1.11.2)
CVE-2023-37918 7.5 - High - July 21, 2023

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that allows bypassing API token authentication, which is used by the Dapr sidecar to authenticate calls coming from the application, with a well-crafted HTTP request. Users who leverage API token authentication are encouraged to upgrade Dapr to 1.10.9 or to 1.11.2. This vulnerability impacts Dapr users who have configured API token authentication. An attacker could craft a request that is always allowed by the Dapr sidecar over HTTP, even if the `dapr-api-token` in the request is invalid or missing. The issue has been fixed in Dapr 1.10.9 or to 1.11.2. There are no known workarounds for this vulnerability.

authentification

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Linux Foundation Dapr or by Linux Foundation? Click the Watch button to subscribe.

subscribe