CVE-2024-38368Disclosure(cocoapods / trunk.cocoapods.org)

LOWCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for cocoapods trunk.cocoapods.org systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also possible to have all owners removed from a pod, and that made the pod available for the same claiming system. This was patched server-side in commit 71be5440906b6bdfbc0bcc7f8a9fec33367ea0f4 in September 2023.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trunk.cocoapods.org

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
trunk.cocoapods.org

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-05-04: 1Active Exploitation · 2026-05-04: 1Technical Details · 2026-02-03: 1Technical Details · 2026-05-04: 102-0305-04
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • SecureChap@SecureChap
    Disclosure

    Nineteen years separate the first cataloged package manager path traversal (CVE-2007-0469) from this year's rediscovery (CVE-2026-34591, CVE-2026-35206). Same bug class. Same archive-extraction primitive. Different ecosystem. A new survey by Nesbitt catalogs a dozen CWE patterns that hit npm, PyPI, RubyGems, Composer, Cargo, Go, Helm, NuGet, and Conda over and over. A few standouts: Argument injection into VCS tools - six separate CVEs in one tool alone across git, hg, and Perforce wrappers (CVE-2021-29472, CVE-2022-36069, CVE-2021-43809, CVE-2023-5752, CVE-2022-24440, plus one more). Integrity checks that fail open: CVE-2016-1252 (clearsigned parser accepted unsigned content), CVE-2022-31156 (sig check silently skipped on error), CVE-2022-46176 (missing SSH host key on git index clones). Dependency confusion was already CVE-2013-0334 - eight years before its 2021 fame. Terminal escape sequences in package metadata: at least nine CVEs across four ecosystems. CocoaPods CVE-2024-38368: an orphaned admin API was left in place for ten years, until a researcher used it to claim 1,800 packages. The thesis: knowledge doesn't transfer between projects. Every ecosystem rediscovers the same dozen bugs from scratch. http://nesbitt.io/2026/05/04/package-manager-cwes.html

    Post summary

    The post surveys repeated CWEs across major package ecosystems, noting newly discovered path traversal and injection bugs while highlighting previous findings such as the CocoaPods admin‑API misuse, thereby underscoring knowledge gaps but offering no exploit or patch details.

    0000043
    44 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Bytes Crate for Rust, Integer Overflow, #CVE-2024-38368 (Critical) https://dailycve.com/bytes-crate-for-rust-integer-overflow-cve-2024-38368-critical/

    Post summary

    An integer overflow vulnerability (CVE-2024-38368) in Bytes Crate for Rust was disclosed as critical, with a reference to a dailycve article, but no PoC, exploit, or patch details were provided.

    0000041
    162 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcocoapodstrunk.cocoapods.org---

Explore more