Red Hat OpenShift Container Platform

63 known vulnerabilities in Red Hat OpenShift Container Platform, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-96577 CVSS 7.1 high A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without…
  • CVE-2026-83589 CVSS 6.1 medium A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login…
  • CVE-2026-101295 CVSS 7.3 high Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the…
  • CVE-2026-62146 CVSS 7.8 high A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved…
  • CVE-2026-102010 CVSS 7.0 high A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library…
  • CVE-2026-87114 CVSS 7.1 high A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container…
  • CVE-2026-93834 CVSS 8.8 high A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when…
  • CVE-2026-75887 CVSS 7.5 high A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the…
  • CVE-2026-75886 CVSS 7.2 high A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which…
  • CVE-2026-94640 CVSS 7.5 high A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a…
  • CVE-2026-90462 CVSS 5.4 medium A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a…
  • CVE-2026-95619 CVSS 7.7 high A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library…
  • CVE-2026-95508 CVSS 7.4 high A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small…
  • CVE-2026-75939 CVSS 7.4 high A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for…
  • CVE-2026-92574 CVSS 8.8 high A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the…
  • CVE-2026-15801 CVSS 8.0 high A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers…
  • CVE-2026-75885 CVSS 9.3 critical A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a…
  • CVE-2026-81627 CVSS 8.2 high A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the…
  • CVE-2026-76781 CVSS 5.5 medium A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference…
  • CVE-2026-42784 CVSS 7.4 high A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is…
  • CVE-2025-11395 CVSS 5.5 medium A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host…
  • CVE-2026-79705 CVSS 4.5 medium A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing…
  • CVE-2026-79699 CVSS 4.4 medium A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can…
  • CVE-2026-90996 CVSS 4.0 medium A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security…
  • CVE-2026-90995 CVSS 5.5 medium A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable…
  • CVE-2026-90994 CVSS 4.0 medium A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser…
  • CVE-2026-90463 CVSS 4.0 medium A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted…
  • CVE-2026-89329 CVSS 6.2 medium A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by…
  • CVE-2026-84828 CVSS 6.5 medium A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs…
  • CVE-2026-88265 CVSS 5.6 medium A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio…