About “Mule Runtime”

A curated feed of “Mule Runtime”-related CVEs appears below. We currently track 5 CVEs for this tag (all time). In the last 365 days, 0 were published. Average CVSS is 8.9 (all time), and 100% are rated High/Critical (all time). Top CWEs (all time): CWE-611 - Improper Restriction of XML External Entity Reference, CWE-918 - Server-Side Request Forgery (SSRF), CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').

In our taxonomy this topic maps to a LOW impact class. Integration platforms and ESBs bridge systems. Patch runtimes and connectors, restrict admin consoles, validate signer keys, and monitor flows. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

Support & lifecycle: mulesoft-runtime

This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.

CycleReleaseLatestPremier SupportEOLLTS
4.114.11.2 Soon
4.104.10.5 Soon
4.9-lts4.9.16LTS
4.94.9.16 Expired
4.84.8.6 Expired
4.74.7.4 Expired
4.6-lts4.6.22
4.64.6.22 Expired
4.54.5.3 Expired
4.44.4.0-20250919 Expired
4.34.3.0-20240424 Expired
4.24.2.2-20221027 Expired
4.14.1.6-20240112 Expired
3.93.9.5-20240122 ExpiredLTS
3.83.8.7 ExpiredLTS

Maintained Soon (≤ 180 days) Expired

Subscribe lifecycle: RSS  ·  RSS (expired)  ·  ICS

Subscribe CVEs: RSS for “Mule Runtime”  ·  RSS (High+Critical only)

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2021-08-05
High

CVE-2021-1630

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on…

2021-03-26
Critical

CVE-2021-1628

MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Affected versions: Mule 4…

Critical

CVE-2021-1627

MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. This affects: Mule 3.8.…

Critical

CVE-2021-1626

MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub and on-premise customers. Versions affected: Mule 4.1.x…

2019-08-30
High

CVE-2019-15630

Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released…

CVE Daily Lookup — auto-links CVE IDs on any page you visit. GitHub, Jira, Confluence & more. Free.