CWE-1357: Reliance on Insufficiently Trustworthy Component
The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.
8 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-28042 — SUBNET PowerSYSTEM Center Reliance on Insufficiently Trustworthy Component
- CVE-2024-26024 — SUBNET Substation Server Reliance on Insufficiently Trustworthy Component
- CVE-2025-32800 — Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencies not present in PyPI
- CVE-2026-75569 — Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha
- CVE-2026-47619 — NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A s
- CVE-2026-67275 — Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi
- CVE-2026-66783 — Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
Recently published
- CVE-2026-67275 — Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi
- CVE-2026-75569 — Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha
- CVE-2026-66783 — Submariner-operator: release workflow consumes same-org composite action via mutable @devel branch ref
- CVE-2026-47619 — NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A s
- CVE-2025-32800 — Conda-build vulnerable to supply chain attack vector due to pyproject.toml referring to dependencies not present in PyPI
- CVE-2024-26024 — SUBNET Substation Server Reliance on Insufficiently Trustworthy Component
- CVE-2024-28042 — SUBNET PowerSYSTEM Center Reliance on Insufficiently Trustworthy Component