Red Hat OpenStack Platform
11 known vulnerabilities in Red Hat OpenStack Platform, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-93834 CVSS 8.8 high A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when…
- CVE-2026-81627 CVSS 8.2 high A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the…
- CVE-2026-92091 CVSS 5.9 medium A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with…
- CVE-2026-75092 CVSS 7.3 high A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to…
- CVE-2026-84828 CVSS 6.5 medium A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs…
- CVE-2026-87874 CVSS 8.1 high A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records…
- CVE-2026-87872 CVSS 6.8 medium A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request…
- CVE-2026-84185 CVSS 5.9 medium A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The…
- CVE-2026-80179 CVSS 5.9 medium A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period…
- CVE-2026-80158 CVSS 5.5 medium A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply…
- CVE-2026-27137 CVSS 7.5 high When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local…