Skip to content
Tools / OctoPrint / Security

Security Deep Dive

OctoPrint

Security posture and CVE patch evidence from tracked releases.

Back to Tool

2 critical dependency CVEs affects 1.11.8.

Audit transitive dependencies; consider upgrading or pinning replacements.

— Signed — SLSA — SBOM ✓ Security policy Quarterly cadence · 72d median Active maintainer

Trust Signals — 3 of 9 Present

Evidence already collected from releases and repository metadata.

3/9 Present
Signed releases Unknown
Latest release artifact signature Latest release
SLSA provenance Unknown
Attestation predicate level Latest release
SBOM published Unknown
GitHub SBOM API Latest release
SECURITY.md Present
GitHub repository metadata Repository policy
Checked: 13d ago
Release cadence: quarterly Present
72d median over recent releases Release history
Latest release: 1mo ago
Maintainer active Present
Recent commit activity Repository
Last commit: 9d ago
Checksums (SHA256SUMS) Not active yet
SHA256SUMS or equivalent Release asset
Latest release: 1mo ago
GitHub Actions attestation Not active yet
actions/attest-build-provenance Workflow file
Latest release: 1mo ago
Signing assets Not active yet
.sig, .crt, cosign.pub, or similar Release asset
Latest release: 1mo ago
3.9/10 Security Score
5.3/10 Scorecard
Pending CVE Patch Speed
Open CVEs Open CVEs detected for latest version.

Security Score

A composite score aggregating Scorecard performance, CVE patch history, OpenSSF badge tier, and dependency vulnerability exposure. Score ≥ 7.0 is healthy; < 4.0 warrants attention.

epss

0.25 / 0.5

No EPSS data

freshness

1.00 / 1.0

2d stale

scorecard

2.12 / 4.0

Score 5.3/10

cve health

0.00 / 2.5

Open CVEs detected

patch speed

0.50 / 0.5

⚠ Estimated — no CVE patch history

kev exposure

1.50 / 1.5

No KEV exposure

supply chain risk

-1.50 / 10.0

Risk 56.4/100

Score breakdown

schema v2

Vulnerability posture

vulnerability posture

0.0

25%

direct cves: open cve scan: available

Release responsiveness

release responsiveness

10.0

5%

patch speed days: no_history

Dependency exposure

dependency exposure

4.4

10%

supply chain risk: 56.35 transitive cves: 2c/24h

Provenance trust

provenance trust

5.3

40%

scorecard score: 5.3 openssf badge: none

Maintainer health

maintainer health

10.0

10%

activity freshness: 2d

Operational risk

operational risk

8.5

10%

kev exposure: clear epss max: none
How is this calculated?

The six dimensions group the legacy score signals into weighted categories: direct vulnerability status, patch responsiveness, dependency exposure, provenance checks, maintainer activity, and exploitability risk. The flat component values above remain available for compatibility.

Supply Chain Risk

Risk 56.4/100
2 Transitive critical CVEs
0 KEV-transitive CVEs
82% Dependency freshness

Scorecard

Scorecard 5.3/10

OpenSSF Scorecard evaluates supply-chain security practices automatically. Score ≥ 6 is passing; ≥ 8 is excellent.

Check Score Reason
Maintained 10 30 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10
Security-Policy 10 security policy file detected
Code-Review 2 Found 6/30 approved changesets -- score normalized to 2
Dangerous-Workflow 10 no dangerous workflow patterns detected
Token-Permissions 0 detected GitHub workflow tokens with excessive permissions
CII-Best-Practices 0 no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts 9 binaries present in source code
License 10 license file detected
Branch-Protection -1 internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases 0 Project has not signed or included provenance with any releases.
Fuzzing 0 project is not fuzzed
SAST 0 SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies 5 dependency not pinned by hash detected -- score normalized to 5
Packaging 10 packaging workflow detected

OpenSSF Badge

OpenSSF none

Badge indicates adherence to open-source best practices.

Dependency Vulnerabilities

79 dependencies scanned View full dependency list →

Scanning the SBOM (Software Bill of Materials) of the latest release for known vulnerabilities in transitive dependencies.

Critical

2

High

24

Medium

17

Low

3

Unknown

4

Critical 2 High 24 Medium 17 Low 3 Unknown 4
CVE Severity KEV Dependency Affected version Cleared in release
CVE-2017-18342 critical pyyaml 6.0.3,< 7 1.11.8
CVE-2020-14343 critical pyyaml 6.0.3,< 7 1.11.8
CVE-2012-2374 high tornado 6.5.5,< 6.6 1.11.8
CVE-2012-2921 high feedparser 6.0.12,< 7 1.11.8
CVE-2013-1633 high setuptools 1.11.8
CVE-2014-9720 high tornado 6.5.5,< 6.6 1.11.8
CVE-2018-1000656 high flask 3.1.3,< 3.2 1.11.8
CVE-2019-1010083 high flask 3.1.3,< 3.2 1.11.8
CVE-2019-14322 high werkzeug 3.1.8,< 3.2 1.11.8
CVE-2019-14806 high werkzeug 3.1.8,< 3.2 1.11.8
CVE-2019-18874 high psutil 7.2.2,< 8 1.11.8
CVE-2021-42771 high babel 2.18,< 2.19 1.11.8
CVE-2022-40897 high setuptools 1.11.8
CVE-2022-40898 high wheel 1.11.8
CVE-2022-40899 high future 1.11.8
CVE-2023-25577 high werkzeug 3.1.8,< 3.2 1.11.8
CVE-2023-28117 high sentry-sdk 2.58.0,< 3 1.11.8
CVE-2023-30861 high flask 3.1.3,< 3.2 1.11.8
CVE-2024-34069 high werkzeug 3.1.8,< 3.2 1.11.8
CVE-2024-52804 high tornado 6.5.5,< 6.6 1.11.8
CVE-2024-6345 high setuptools 1.11.8
CVE-2025-47273 high setuptools 1.11.8
CVE-2025-47287 high tornado 6.5.5,< 6.6 1.11.8
CVE-2026-24049 high wheel 1.11.8
CVE-2026-31958 high tornado 6.5.5,< 6.6 1.11.8
CVE-2026-35536 high tornado 6.5.5,< 6.6 1.11.8
CVE-2009-5065 medium feedparser 6.0.12,< 7 1.11.8
CVE-2016-10516 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2020-28724 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2021-29510 medium pydantic 2.13.0,< 3 1.11.8
CVE-2023-28370 medium tornado 6.5.5,< 6.6 1.11.8
CVE-2023-46136 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2024-3772 medium pydantic 2.13.0,< 3 1.11.8
CVE-2024-49766 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2024-49767 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2025-66221 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2026-21860 medium werkzeug 3.1.8,< 3.2 1.11.8
CVE-2026-25645 medium requests 2.32.5 1.11.8
CVE-2026-27199 medium werkzeug 3.1.8,< 3.2 1.11.8
GHSA-753j-mpmx-qq6g medium tornado 6.5.5,< 6.6 1.11.8
GHSA-78cv-mqj4-43f7 medium tornado 6.5.5,< 6.6 1.11.8
GHSA-qppv-j76h-2rpx medium tornado 6.5.5,< 6.6 1.11.8
GHSA-w235-7p84-xx57 medium tornado 6.5.5,< 6.6 1.11.8
CVE-2023-23934 low werkzeug 3.1.8,< 3.2 1.11.8
CVE-2024-40647 low sentry-sdk 2.58.0,< 3 1.11.8
CVE-2026-27205 low flask 3.1.3,< 3.2 1.11.8
CVE-2011-1156 unknown feedparser 6.0.12,< 7 1.11.8
CVE-2011-1157 unknown feedparser 6.0.12,< 7 1.11.8
CVE-2011-1158 unknown feedparser 6.0.12,< 7 1.11.8
CVE-2022-29361 unknown werkzeug 3.1.8,< 3.2 1.11.8

Showing 50 of 50

Beta — feedback welcome: [email protected]