[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-12289":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":34,"aliases":35,"duplicate_of":9,"upstream":38,"downstream":39,"duplicates":42,"related":43,"reserved_at":9,"published_at":45,"modified_at":46,"state":47,"summary":48,"references_raw":57,"kevs":80,"epss":81,"epss_history":84,"metrics":354,"affected":364},"CVE-2024-12289","Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process.\n\nThis vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.",null,[11,20],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-460","Improper Cleanup on Thrown Exception","The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.","weakness","Draft","Base","Medium",[],{"_key":21,"id":21,"name":22,"description":23,"type":15,"status":16,"abstraction":24,"likelihood_of_exploit":18,"capec":25},"CWE-665","Improper Initialization","The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.","Class",[26,30],{"id":27,"name":28,"techniques":29},"CAPEC-26","Leveraging Race Conditions",[],{"id":31,"name":32,"techniques":33},"CAPEC-29","Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions",[],[],[36,37],"GHSA-xx83-cxmq-x89m","GO-2024-3335",[],[40],{"_key":41},"OPENSUSE-SU-2024:14603-1",[],[44],{"_key":41},"2024-12-12T22:42:01.595Z","2024-12-13T19:35:10.676Z","Analyzed",{"cisa_kev":49,"cisa_ransomware":49,"cisa_vendor":9,"epss_severity":50,"epss_score":51,"severity":52,"severity_score":53,"severity_version":54,"severity_source":55,"severity_vector":56,"severity_status":47},false,"low",0.00392,"medium",5.9,"v3.1","cve.org","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",[58,66,71,76],{"url":59,"sources":60,"tags":63},"https://discuss.hashicorp.com/t/hcsec-2024-28-boundary-controller-incorrectly-handles-http-requests-on-initialization-which-may-lead-to-a-denial-of-service",[55,61,62],"nvd","osv_go",[64,65],"Vendor Advisory","WEB",{"url":67,"sources":68,"tags":69},"https://nvd.nist.gov/vuln/detail/CVE-2024-12289",[62],[70],"Advisory",{"url":72,"sources":73,"tags":74},"https://github.com/hashicorp/boundary",[62],[75],"PACKAGE",{"url":77,"sources":78,"tags":79},"https://github.com/advisories/GHSA-xx83-cxmq-x89m",[62],[70],[],{"date":82,"score":51,"percentile":83},"2026-06-04",0.60534,[85,89,92,94,97,100,103,106,109,112,115,118,121,124,127,131,134,137,140,143,146,149,152,155,158,161,164,167,170,173,176,179,182,185,188,190,193,196,199,202,205,208,210,212,215,218,221,224,227,230,232,235,238,241,244,247,250,254,257,260,263,266,269,272,275,278,281,284,287,289,292,295,298,301,304,307,310,313,317,321,324,327,330,333,336,339,343,346,348,351],{"date":86,"score":87,"percentile":88},"2025-11-04",0.0016,0.37433,{"date":90,"score":87,"percentile":91},"2025-11-05",0.37426,{"date":93,"score":87,"percentile":91},"2025-11-06",{"date":95,"score":87,"percentile":96},"2025-11-07",0.37447,{"date":98,"score":87,"percentile":99},"2025-11-08",0.37446,{"date":101,"score":87,"percentile":102},"2025-11-09",0.37431,{"date":104,"score":87,"percentile":105},"2025-11-10",0.37394,{"date":107,"score":87,"percentile":108},"2025-11-11",0.37417,{"date":110,"score":87,"percentile":111},"2025-11-12",0.37457,{"date":113,"score":87,"percentile":114},"2025-11-13",0.3747,{"date":116,"score":87,"percentile":117},"2025-11-14",0.37473,{"date":119,"score":87,"percentile":120},"2025-11-15",0.37472,{"date":122,"score":87,"percentile":123},"2025-11-16",0.37459,{"date":125,"score":87,"percentile":126},"2025-11-17",0.37438,{"date":128,"score":129,"percentile":130},"2025-11-18",0.00271,0.47441,{"date":132,"score":129,"percentile":133},"2025-11-19",0.47455,{"date":135,"score":129,"percentile":136},"2025-11-20",0.47436,{"date":138,"score":87,"percentile":139},"2025-11-21",0.3745,{"date":141,"score":87,"percentile":142},"2025-11-22",0.37454,{"date":144,"score":87,"percentile":145},"2025-11-23",0.37418,{"date":147,"score":87,"percentile":148},"2025-11-24",0.37402,{"date":150,"score":87,"percentile":151},"2025-11-25",0.37408,{"date":153,"score":87,"percentile":154},"2025-11-26",0.37401,{"date":156,"score":87,"percentile":157},"2025-11-27",0.37411,{"date":159,"score":87,"percentile":160},"2025-11-28",0.37388,{"date":162,"score":87,"percentile":163},"2025-11-29",0.37368,{"date":165,"score":87,"percentile":166},"2025-11-30",0.37353,{"date":168,"score":87,"percentile":169},"2025-12-01",0.37466,{"date":171,"score":87,"percentile":172},"2025-12-02",0.37478,{"date":174,"score":87,"percentile":175},"2025-12-03",0.37476,{"date":177,"score":87,"percentile":178},"2025-12-04",0.37351,{"date":180,"score":87,"percentile":181},"2025-12-05",0.37384,{"date":183,"score":87,"percentile":184},"2025-12-06",0.37383,{"date":186,"score":87,"percentile":187},"2025-12-07",0.37354,{"date":189,"score":87,"percentile":163},"2025-12-08",{"date":191,"score":87,"percentile":192},"2025-12-09",0.37406,{"date":194,"score":87,"percentile":195},"2025-12-10",0.37468,{"date":197,"score":87,"percentile":198},"2025-12-11",0.37496,{"date":200,"score":87,"percentile":201},"2025-12-12",0.37533,{"date":203,"score":87,"percentile":204},"2025-12-13",0.37513,{"date":206,"score":87,"percentile":207},"2025-12-14",0.37475,{"date":209,"score":87,"percentile":96},"2025-12-15",{"date":211,"score":87,"percentile":207},"2025-12-16",{"date":213,"score":87,"percentile":214},"2025-12-17",0.37521,{"date":216,"score":87,"percentile":217},"2025-12-18",0.37567,{"date":219,"score":87,"percentile":220},"2025-12-19",0.37587,{"date":222,"score":87,"percentile":223},"2025-12-20",0.37566,{"date":225,"score":87,"percentile":226},"2025-12-21",0.3751,{"date":228,"score":87,"percentile":229},"2025-12-22",0.37486,{"date":231,"score":87,"percentile":229},"2025-12-23",{"date":233,"score":87,"percentile":234},"2025-12-24",0.37499,{"date":236,"score":87,"percentile":237},"2025-12-25",0.37555,{"date":239,"score":87,"percentile":240},"2025-12-26",0.3754,{"date":242,"score":87,"percentile":243},"2025-12-27",0.37563,{"date":245,"score":87,"percentile":246},"2025-12-28",0.37458,{"date":248,"score":87,"percentile":249},"2025-12-29",0.37432,{"date":251,"score":252,"percentile":253},"2025-12-30",0.00196,0.41791,{"date":255,"score":252,"percentile":256},"2025-12-31",0.41837,{"date":258,"score":252,"percentile":259},"2026-01-01",0.41971,{"date":261,"score":252,"percentile":262},"2026-01-02",0.41945,{"date":264,"score":252,"percentile":265},"2026-01-03",0.41935,{"date":267,"score":252,"percentile":268},"2026-01-04",0.41778,{"date":270,"score":252,"percentile":271},"2026-01-05",0.41753,{"date":273,"score":252,"percentile":274},"2026-01-06",0.41754,{"date":276,"score":252,"percentile":277},"2026-01-07",0.41776,{"date":279,"score":252,"percentile":280},"2026-01-08",0.41803,{"date":282,"score":252,"percentile":283},"2026-01-09",0.41786,{"date":285,"score":252,"percentile":286},"2026-01-10",0.41785,{"date":288,"score":252,"percentile":274},"2026-01-11",{"date":290,"score":252,"percentile":291},"2026-01-12",0.41706,{"date":293,"score":252,"percentile":294},"2026-01-13",0.41683,{"date":296,"score":252,"percentile":297},"2026-01-14",0.41732,{"date":299,"score":252,"percentile":300},"2026-01-15",0.41724,{"date":302,"score":252,"percentile":303},"2026-01-16",0.41745,{"date":305,"score":252,"percentile":306},"2026-01-17",0.4172,{"date":308,"score":252,"percentile":309},"2026-01-18",0.41687,{"date":311,"score":252,"percentile":312},"2026-01-19",0.41654,{"date":314,"score":315,"percentile":316},"2026-01-20",0.00317,0.54319,{"date":318,"score":319,"percentile":320},"2026-01-21",0.00369,0.58219,{"date":322,"score":319,"percentile":323},"2026-01-22",0.58218,{"date":325,"score":319,"percentile":326},"2026-01-23",0.58256,{"date":328,"score":319,"percentile":329},"2026-01-24",0.58263,{"date":331,"score":319,"percentile":332},"2026-01-25",0.58227,{"date":334,"score":319,"percentile":335},"2026-01-26",0.5821,{"date":337,"score":319,"percentile":338},"2026-01-27",0.5822,{"date":340,"score":341,"percentile":342},"2026-01-28",0.00513,0.6592,{"date":344,"score":51,"percentile":345},"2026-01-29",0.59693,{"date":347,"score":51,"percentile":345},"2026-01-30",{"date":349,"score":51,"percentile":350},"2026-01-31",0.59699,{"date":352,"score":51,"percentile":353},"2026-02-01",0.59831,[355,360,362],{"source":55,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":356,"cvss_v4_0":9},{"baseScore":53,"baseSeverity":357,"vectorString":56,"impactScore":358,"exploitabilityScore":359},"MEDIUM",6,5.6,{"source":61,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":361,"cvss_v4_0":9},{"baseScore":53,"baseSeverity":357,"vectorString":56,"impactScore":358,"exploitabilityScore":359},{"source":62,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":363,"cvss_v4_0":9},{"baseScore":53,"baseSeverity":9,"vectorString":56,"impactScore":358,"exploitabilityScore":359},[365,378,398],{"ecosystem":366,"name":367,"vendor":368,"product":369,"cpe_part":9,"purl_type":370,"purl_namespace":368,"purl_name":369,"source":9,"versions":371},"Go","github.com/hashicorp/boundary","github.com/hashicorp","boundary","golang",[372],{"version":373,"is_range":374,"range_type":375,"version_start":9,"version_start_type":9,"version_end":376,"version_end_type":377,"fixed_in":9},"lt0_18_2",true,"semver","0.18.2","excluding",{"ecosystem":9,"name":379,"vendor":380,"product":369,"cpe_part":381,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":382},"Boundary","hashicorp","a",[383,387,391,395],{"version":384,"is_range":374,"range_type":55,"version_start":385,"version_start_type":386,"version_end":376,"version_end_type":377,"fixed_in":9},">= 0.8.0, \u003C 0.18.2","0.8.0","including",{"version":388,"is_range":374,"range_type":389,"version_start":385,"version_start_type":386,"version_end":390,"version_end_type":377,"fixed_in":9},"gte0.8.0_lt0.16.4","cpe","0.16.4",{"version":392,"is_range":374,"range_type":389,"version_start":393,"version_start_type":386,"version_end":394,"version_end_type":377,"fixed_in":9},"gte0.17.0_lt0.17.3","0.17.0","0.17.3",{"version":396,"is_range":374,"range_type":389,"version_start":397,"version_start_type":386,"version_end":376,"version_end_type":377,"fixed_in":9},"gte0.18.0_lt0.18.2","0.18.0",{"ecosystem":9,"name":399,"vendor":380,"product":400,"cpe_part":381,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":401},"Boundary Enterprise","boundary enterprise",[402],{"version":384,"is_range":374,"range_type":55,"version_start":385,"version_start_type":386,"version_end":376,"version_end_type":377,"fixed_in":9}]