<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Teleport</title>
  <link>https://cvedaily.com/pages/tags/teleport.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/teleport.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Teleport</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:06 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-49825 – Teleport provides connectivity, authentication, access controls and audit for in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49825</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49825</guid>
    <pubDate>Tue, 17 Jun 2025 22:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49825</strong></p>
  <p>Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49825">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-28855 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28855</guid>
    <pubDate>Wed, 26 Mar 2025 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-28855</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in srcoley Teleport teleport allows Reflected XSS.This issue affects Teleport: from n/a through <= 1.2.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-38599 – Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38599</guid>
    <pubDate>Thu, 08 Dec 2022 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-38599</strong></p>
  <p>Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38599">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
