Redhat
Redhat Openshift Container Platform: vulnerabilities and CVEs
Redhat Openshift Container Platform has 328 published vulnerabilities, 60 of them in the last 12 months. 39 are rated critical and 8 are listed by CISA as actively exploited.
CVEs328
Last 12 months60
Critical39
Actively exploited8
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31431 | High (7.8) | 3.4% | ⚠ Active exploitation | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2021-3560 | High (7.8) | 24% | ⚠ Active exploitation | Feb 16, 2022 | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker… |
| CVE-2019-1003029 | Critical (9.9) | 74% | ⚠ Active exploitation | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java,… |
| CVE-2019-1003030 | Critical (9.9) | 97% | ⚠ Active exploitation | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline… |
| CVE-2018-1000861 | Critical (9.8) | 98% | ⚠ Active exploitation | Dec 10, 2018 | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to… |
| CVE-2019-7609 | Critical (10) | 95% | ⚠ Active exploitation | Mar 25, 2019 | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute… |
| CVE-2019-0211 | High (7.8) | 65% | ⚠ Active exploitation | Apr 8, 2019 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter)… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92574 | High (8.8) | 0.65% | — | Sep 21, 2026 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials,… |
| CVE-2026-13002 | Medium (4.4) | 0.15% | — | Aug 14, 2026 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS… |
| CVE-2026-19617 | Medium (5.5) | 0.14% | — | Aug 14, 2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration… |
| CVE-2026-19548 | Medium (5.5) | 0.15% | — | Aug 12, 2026 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the… |
| CVE-2026-71227 | Medium (5.1) | 0.17% | — | Aug 5, 2026 | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the… |
| CVE-2026-71226 | High (7.3) | 0.18% | — | Aug 5, 2026 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers. |
| CVE-2026-71225 | Medium (6.5) | 0.52% | — | Aug 5, 2026 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the… |
| CVE-2026-68743 | High (7.1) | 0.13% | — | Aug 4, 2026 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a… |
| CVE-2026-68744 | Low (3.3) | 0.13% | — | Aug 4, 2026 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized… |
| CVE-2026-18477 | Medium (4.4) | 0.08% | — | Aug 3, 2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the… |
| CVE-2026-18508 | Medium (4.4) | 0.14% | — | Aug 3, 2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working… |
| CVE-2026-68742 | Medium (5.5) | 0.13% | — | Aug 3, 2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted… |
| CVE-2026-13757 | Medium (6.2) | 0.20% | — | Jun 29, 2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit… |
| CVE-2026-13595 | Medium (5.3) | 0.17% | — | Jun 29, 2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically… |
| CVE-2026-55653 | Medium (6.5) | 0.51% | — | Jun 23, 2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards)… |
| CVE-2026-12725 | Medium (5.9) | 0.53% | — | Jun 22, 2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write… |
| CVE-2026-54100 | High (8.3) | 0.30% | — | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An… |
| CVE-2026-54099 | High (8.8) | 0.11% | — | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization… |
| CVE-2026-44495 | High (7.7) | 1.0% | — | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same… |
| CVE-2026-1784 | High (8.8) | 0.19% | — | Jun 2, 2026 | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and… |
| CVE-2026-10533 | Medium (5) | 0.23% | — | Jun 1, 2026 | A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create… |
| CVE-2026-46579 | High (7.5) | 0.62% | — | May 29, 2026 | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated… |
| CVE-2026-42965 | Medium (6.5) | 0.47% | — | May 29, 2026 | A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a… |
| CVE-2026-4408 | Critical (9.8) | 1.8% | — | May 28, 2026 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u… |
| CVE-2026-2340 | Medium (6.5) | 0.94% | — | May 27, 2026 | A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient… |
| CVE-2026-1933 | Medium (6.5) | 0.86% | — | May 27, 2026 | A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may… |
| CVE-2026-3012 | Medium (6.8) | 0.23% | — | May 27, 2026 | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the… |
| CVE-2026-48864 | High (7.8) | 0.26% | — | May 26, 2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a… |
| CVE-2026-4480 | Critical (9.8) | 4.3% | — | May 26, 2026 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping… |
| CVE-2026-9149 | Medium (6.5) | 0.57% | — | May 21, 2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an… |
Other products by Redhat
Enterprise Linux · 1,937Enterprise Linux Desktop · 1,928Enterprise Linux Server · 1,891Enterprise Linux Workstation · 1,845Enterprise Linux Server AUS · 1,059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230Openstack · 210