GO-2024-3040: Juju's unprivileged user running on charm node can leak any secret or relation data accessible to the local charm in github.com/juju/juju
GO-2024-3173: JUJU_CONTEXT_ID is a predictable authentication secret in github.com/juju/juju
GO-2024-3174: Vulnerable juju hook tool abstract UNIX domain socket in github.com/juju/juju
GO-2024-3175: Vulnerable juju introspection abstract UNIX domain socket in github.com/juju/juju
GO-2025-3639: Juju uses a UNIX domain socket without setting appropriate permissions in github.com/juju/juju
GO-2025-3804: Juju zip slip vulnerability via authenticated endpoint in github.com/juju/juju
GO-2025-3805: Juju allows arbitrary executable uploads via authenticated endpoint without authorization in github.com/juju/juju
GO-2025-3806: Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorization in github.com/juju/juju