github.com/tilt-dev/tilt
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/tilt-dev/tiltpage 1 of 1
- CVE-2026-55882HIGHCVSS 8.3EG 8.3✓ Fixed in 0.37.42026-06-19
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug with no access control. When the HUD or apiserver listener is network…
- CVE-2026-55883HIGHCVSS 8.3EG 8.3✓ Fixed in 0.37.42026-06-19
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoin…
- CVE-2026-55884CRITICALCVSS 9.2EG 9.2✓ Fixed in 0.37.42026-06-19
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-lo…
Check whether github.com/tilt-dev/tilt is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/tilt-dev/tilt CVEs against the assets you own.
Start Free Scan →