CVEs we hold for Palantir
Records whose assigning authority named Palantir as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-68609Authentication bypass in Aries due to misconfigurationPalantir com.palantir.aries:aries
CVE-2025-64400Insufficient permission checks when pre-enrolling users SummaryPalantir com.palantir.controlpanel:control-panel
CVE-2025-62487Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings…Palantir com.palantir.acme:dossier-app
CVE-2025-53710Network boundaries not respected in certain Foundry namespaces.Palantir com.palantir.codeassist2:code-assist-proxy
CVE-2025-53709Access control issues impacting secure-upload servicePalantir com.palantir.secupload:secure-upload
CVE-2024-49588Multiple authenticated SQL injections in oracle-sidecarPalantir com.palantir.srx.prometheus.sls-oracle-sidecar:sls-…
CVE-2024-49581Access control issue impacting RV backed objectsPalantir com.palantir.gotham:external-artifacts
CVE-2023-30970Gotham table and Forward App Path traversalPalantir com.palantir.gotham:blackbird-witchcraft
CVE-2023-30969Palantir Tiles missing authentication on API endpointsPalantir com.palantir.tiles:tiles
CVE-2023-30963Stored XSS in Foundry Slate Query Dropdown menuPalantir com.palantir.foundry:foundry-frontend
CVE-2023-30961Palantir Gotham UI bug that could lead to incorrect data classificationPalantir com.palantir.acme:titanium-browser-app-bundle
CVE-2023-30960Insecure Direct Object Reference (IDOR) in Foundry job-trackerPalantir com.palantir.foundry.jobtracker:job-tracker
CVE-2023-30959Stored XSS via javascript URI in Apollo Change Requests commentPalantir com.palantir.apollo:autopilot
CVE-2023-30958DOM XSS in Developer mode dashboard via redirect GET parameterPalantir com.palantir.foundry:foundry-frontend
CVE-2023-30956IDOR in Foundry Comments allows retrieval of attachmentsPalantir com.palantir.comments:comments
CVE-2023-30955Foundry workspace-server Developer Mode Authorization BypassPalantir com.palantir.workspace:workspace
CVE-2023-30954Gotham Video Broken AuthenticationPalantir com.palantir.video:video-application-server
CVE-2023-30952Foundry Issues reporterPath phishing by parameter injectionPalantir com.palantir.foundry:foundry-frontend
CVE-2023-30948Retrieval of Attachments to Comments lacks AuthorizationPalantir com.palantir.comments:comments
CVE-2023-22836In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes the linter name…Palantir com.palantir.skywise:guardian
CVE-2023-22834The contour service was not checking that users had permission to create an analysis for a given datasetPalantir com.palantir.contour:contour-dispatch
CVE-2022-48306Gotham Chat IRC help does not validate hostnames in TLS certificatesPalantir Gotham Chat IRC helper
CVE-2022-27897Palantir Gotham included an endpoint that would log arbitrary sized zip files.Palantir Gotham
CVE-2022-27896The Foundry Code-Workbooks service was found to contain an issue leading to information disclosure.Palantir Foundry Code-Workbooks
CVE-2022-27895A component in Foundry logging was found to be capturing sensitive information in logs.Palantir Foundry Build2
CVE-2022-27894The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability.Palantir Foundry Blobster Service
CVE-2022-27893The Foundry Magritte plugin osisoft-pi-web-connector was found to be logging in a manner that captured authentication…Palantir Foundry Magritte plugin osisoft-pi-web-connector
CVE-2022-27892Palantir Gotham included an endpoint that would log arbitrary sized payloads.Palantir Gotham
CVE-2022-27891Palantir Gotham included an unauthenticated endpoint that listed all active usernames in the platform with an active…Palantir Gotham
CVE-2022-27889The Foundry Multipass service contains code paths that could be abused to cause a denial of service for authentication…Palantir Foundry Multipass
CVE-2022-27888The Foundry Issues service was found to be logging in a manner that captured session tokens.Palantir Foundry Issues
47 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.