Red Hat OpenShift Dev Spaces

12 known vulnerabilities in Red Hat OpenShift Dev Spaces, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-91149 CVSS 7.5 high A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous…
  • CVE-2026-91147 CVSS 5.9 medium A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by…
  • CVE-2026-91142 CVSS 3.6 low A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for…
  • CVE-2026-87743 CVSS 7.5 high A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the…
  • CVE-2025-11395 CVSS 5.5 medium A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host…
  • CVE-2026-79705 CVSS 4.5 medium A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing…
  • CVE-2026-79699 CVSS 4.4 medium A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can…
  • CVE-2026-42264 CVSS 9.1 critical Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties…
  • CVE-2026-24842 CVSS 8.2 high node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses…
  • CVE-2025-11065 CVSS 5.3 medium A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This…
  • CVE-2026-23950 CVSS 5.9 medium node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete…
  • CVE-2026-23745 CVSS 8.2 high node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries…