Red Hat Cluster Observability Operator
17 known vulnerabilities in Red Hat Cluster Observability Operator, 4 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-13676 CVSS 7.5 high fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path…
- CVE-2026-48779 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to…
- CVE-2026-12143 CVSS 8.7 high form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to…
- CVE-2026-46595 CVSS 10.0 critical Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed…
- CVE-2026-42508 CVSS 9.1 critical Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and…
- CVE-2026-39832 CVSS 9.1 critical When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request…
- CVE-2026-39829 CVSS 7.5 high The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus…
- CVE-2026-6322 CVSS 7.5 high fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters…
- CVE-2026-6321 CVSS 7.5 high fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal()…
- CVE-2026-40895 CVSS 6.9 medium follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior…
- CVE-2025-62718 CVSS 6.3 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname…
- CVE-2026-29181 CVSS 7.5 high OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each…
- CVE-2026-33896 CVSS 9.1 critical Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0…
- CVE-2026-33895 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519…
- CVE-2026-33894 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA…
- CVE-2026-33891 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of…
- CVE-2026-29063 CVSS 8.7 high Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is…