Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
813 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux | 5/8/2026 | 21/9/2026 | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of… | |
| Modificada | Alta (7.3) | 0.18% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux | 5/8/2026 | 21/9/2026 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers. | |
| Modificada | Media (6.5) | 0.52% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux | 5/8/2026 | 21/9/2026 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit… | |
| Analizada | Alta (7.1) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/8/2026 | 31/8/2026 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process… | |
| Analizada | Baja (3.3) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/8/2026 | 31/8/2026 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached… | |
| Modificada | Media (4.4) | 0.08% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or… | |
| Modificada | Media (4.4) | 0.14% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with… | |
| Analizada | Media (5.5) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 31/8/2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash,… | |
| Pendiente de análisis | Alta (8.5) | 0.53% | — | Openshift Oauth-proxyAI | 28/7/2026 | 21/9/2026 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated… | |
| Analizada | Crítica (9.9) | 0.79% | — | Microsoft Azure RED HAT Openshift | 24/7/2026 | 7/8/2026 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Redhat Openshift AIAIRedhat ODH DashboardAI | 23/7/2026 | 30/9/2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the… | |
| Aplazada | Crítica (9) | 0.64% | — | DataeaseAIAmazon Redshift DriverAISpringframework Spring FrameworkAI | 15/7/2026 | 16/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting socketFactory=org.springframework.context.support.FileSystemXmlApplicationContext so… | |
| Aplazada | Alta (7.7) | 0.39% | — | Redhat Openshift GitopsAIArgoproj Argo CDAI | 15/7/2026 | 16/7/2026 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a… | |
| Pendiente de análisis | Alta (8.9) | 0.47% | — | Redhat Openshift GitopsAIArgoproj Argo CDAI | 14/7/2026 | 11/8/2026 | A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Openshift Incluster-checksAI | 13/7/2026 | 14/7/2026 | A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes. | |
| Modificada | Media (6.5) | 0.48% | — | Redhat Openshift AI | 8/7/2026 | 30/9/2026 | A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking, leading to a… | |
| Modificada | Media (6.2) | 0.20% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit | 29/6/2026 | 28/9/2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.… | |
| Modificada | Alta (8.8) | 0.55% | — | Redhat Openshift DEV Spaces | 29/6/2026 | 15/7/2026 | A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an… | |
| Analizada | Media (5.3) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux | 29/6/2026 | 31/8/2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer… | |
| Analizada | Media (4.9) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim into the launcher pod's v1.multus-cni.io/default-network annotation without format validation or sanitization. The only… | |
| Analizada | Baja (3.8) | 0.13% | — | Redhat Openshift VirtualizationKubevirt | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a newline character is received, with no length limit or read deadline. A user with access to a VM guest that has the downward metrics… | |
| Analizada | Media (6.4) | 0.24% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade… | |
| Analizada | Media (4.2) | 0.14% | — | KubevirtRedhat Openshift Virtualization | 26/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink protection. A user with access to the virt-launcher container can plant a symlink at the cache file path, causing virt-handler to… | |
| Analizada | Media (6.5) | 0.13% | — | KubevirtRedhat Openshift Virtualization | 24/6/2026 | 6/7/2026 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connection's origin. Each virt-launcher pod connects through a per-VMI pipe socket, but no… | |
| Modificada | Alta (7.3) | 0.27% | — | KubevirtRedhat Openshift Virtualization | 24/6/2026 | 21/9/2026 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it,… |