Red Hat Logging Subsystem for Red Hat OpenShift

13 known vulnerabilities in Red Hat Logging Subsystem for Red Hat OpenShift, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-46595 CVSS 10.0 critical Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed…
  • CVE-2026-39835 CVSS 5.3 medium SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by…
  • CVE-2026-39832 CVSS 9.1 critical When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request…
  • CVE-2026-39828 CVSS 6.3 medium When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently…
  • CVE-2026-29181 CVSS 7.5 high OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each…
  • CVE-2026-33896 CVSS 9.1 critical Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0…
  • CVE-2026-33895 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519…
  • CVE-2026-33891 CVSS 7.5 high Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of…
  • CVE-2026-29786 CVSS 8.2 high node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the…
  • CVE-2026-3304 CVSS 8.7 high Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to…
  • CVE-2026-2359 CVSS 8.7 high Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to…
  • CVE-2026-24842 CVSS 8.2 high node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses…
  • CVE-2026-23950 CVSS 5.9 medium node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete…