openshift devspaces records
18 published records for vendor openshift devspaces.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 94.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-121 Stack-based Buffer Overflow2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-385 Covert Timing Channel1
- CWE-91 XML Injection (aka Blind XPath Injection)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-44990No exploit | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Critical9.3 | — | 0.7% | Jun 12, 2026 |
37Monitor | CVE-2025-14813No exploit | GOSTCTR implementation unable to process more than 255 blocks correctlylegion of the bouncy castle inc. · bc-java · CWE-327 | Critical9.3 | — | 0.3% | Apr 15, 2026 |
36Monitor | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Critical9.2 | — | 1.0% | May 22, 2026 |
35Monitor | CVE-2026-5598No exploit | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | High8.9 | — | 1.0% | Apr 15, 2026 |
35Monitor | CVE-2026-40611No exploit | Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Providergo-acme · lego · CWE-22 | High8.8 | — | 0.5% | Apr 21, 2026 |
34Monitor | CVE-2026-1761No exploit | Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http responsered hat · red hat enterprise linux 10 · CWE-121 | High8.6 | — | 1.0% | Feb 2, 2026 |
34Monitor | CVE-2026-12143No exploit | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | High8.7 | — | 0.7% | Jun 12, 2026 |
34Monitor | CVE-2026-0719No exploit | Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authenticationred hat · red hat enterprise linux 10 · CWE-121 | High8.6 | — | 0.6% | Jan 8, 2026 |
33Monitor | CVE-2026-0603Proof of concept | Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injectionred hat · red hat jboss enterprise application platform 7.1 eus for rhel 7 · CWE-89 | High8.3 | — | 0.9% | Jan 23, 2026 |
30Monitor | CVE-2026-40984No exploit | Micrometer HTTP server instrumentations DoS vulnerabilityspring · micrometer · CWE-400 | High7.5 | — | 1.1% | Jun 9, 2026 |
30Monitor | CVE-2026-40983No exploit | Micrometer gRPC server instrumentation DoS vulnerabilityspring · micrometer · CWE-400 | High7.5 | — | 0.8% | Jun 9, 2026 |
30Monitor | CVE-2026-34601No exploit | xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertionxmldom · xmldom · CWE-91 | High7.5 | — | 0.5% | Apr 2, 2026 |
30Monitor | CVE-2024-52011Proof of concept | launch-editor vulnerable to command injection via the crafted request on Windowsvitejs · launch-editor · CWE-77 | High7.5 | — | 0.5% | Jun 1, 2026 |
28Monitor | CVE-2026-0775No exploit | npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerabilitynpm · cli · CWE-732 | High7.0 | — | 0.3% | Jan 23, 2026 |
25Monitor | CVE-2026-5588No exploit | PKIX draft CompositeVerifier accepts empty signature sequence as valid.legion of the bouncy castle inc. · bc-java · CWE-327 | Medium6.3 | — | 0.7% | Apr 15, 2026 |
22Monitor | CVE-2026-0636No exploit | LDAP Injection Vulnerability in LDAPStoreHelper.javalegion of the bouncy castle inc. · bc-java · CWE-90 | Medium5.5 | — | 0.5% | Apr 15, 2026 |
21Monitor | CVE-2026-45292No exploit | opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagationopen-telemetry · opentelemetry-java · CWE-770 | Medium5.3 | — | 0.8% | May 28, 2026 |
11Monitor | CVE-2025-69873No exploit | ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enaajv.js · ajv · CWE-1333 | Low2.9 | — | 0.5% | Feb 11, 2026 |
- CVE-2026-4499037Monitor
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CriticalCVSS 9.3No exploitEPSS 1%apostrophecms · sanitize-htmlJun 12, 2026
- CVE-2025-1481337Monitor
GOSTCTR implementation unable to process more than 255 blocks correctly
CriticalCVSS 9.3No exploitEPSS 0%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-927736Monitor
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CriticalCVSS 9.2Proof of conceptEPSS 1%May 22, 2026
- CVE-2026-559835Monitor
Non-constant time comparisons risk private key leakage in FrodoKEM.
HighCVSS 8.9No exploitEPSS 1%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-4061135Monitor
Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
HighCVSS 8.8No exploitEPSS 1%go-acme · legoApr 21, 2026
- CVE-2026-176134Monitor
Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response
HighCVSS 8.6No exploitEPSS 1%red hat · red hat enterprise linux 10Feb 2, 2026
- CVE-2026-1214334Monitor
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
HighCVSS 8.7No exploitEPSS 1%form-data · form-dataJun 12, 2026
- CVE-2026-071934Monitor
Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
HighCVSS 8.6No exploitEPSS 1%red hat · red hat enterprise linux 10Jan 8, 2026
- CVE-2026-060333Monitor
Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
HighCVSS 8.3Proof of conceptEPSS 1%red hat · red hat jboss enterprise application platform 7.1 eus for rhel 7Jan 23, 2026
- CVE-2026-4098430Monitor
Micrometer HTTP server instrumentations DoS vulnerability
HighCVSS 7.5No exploitEPSS 1%spring · micrometerJun 9, 2026
- CVE-2026-4098330Monitor
Micrometer gRPC server instrumentation DoS vulnerability
HighCVSS 7.5No exploitEPSS 1%spring · micrometerJun 9, 2026
- CVE-2026-3460130Monitor
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
HighCVSS 7.5No exploitEPSS 1%xmldom · xmldomApr 2, 2026
- CVE-2024-5201130Monitor
launch-editor vulnerable to command injection via the crafted request on Windows
HighCVSS 7.5Proof of conceptEPSS 1%vitejs · launch-editorJun 1, 2026
- CVE-2026-077528Monitor
npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability
HighCVSS 7.0No exploitEPSS 0%npm · cliJan 23, 2026
- CVE-2026-558825Monitor
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
MediumCVSS 6.3No exploitEPSS 1%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-063622Monitor
LDAP Injection Vulnerability in LDAPStoreHelper.java
MediumCVSS 5.5No exploitEPSS 1%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2026-4529221Monitor
opentelemetry-java: Unbounded Memory Allocation in W3C Baggage Propagation
MediumCVSS 5.3No exploitEPSS 1%open-telemetry · opentelemetry-javaMay 28, 2026
- CVE-2025-6987311Monitor
ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is ena
LowCVSS 2.9No exploitEPSS 1%ajv.js · ajvFeb 11, 2026