OpenShift records
47 published records for vendor openshift.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 93.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-91 XML Injection (aka Blind XPath Injection)4
- CWE-125 Out-of-bounds Read3
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')2
- CWE-130 Improper Handling of Length Parameter Inconsistency2
- CWE-122 Heap-based Buffer Overflow2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
47 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-22797No exploit | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1openstack · keystonemiddleware · CWE-290 | Critical9.9 | — | 0.7% | Jan 19, 2026 |
37Monitor | CVE-2026-44990No exploit | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Critical9.3 | — | 0.7% | Jun 12, 2026 |
36Monitor | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Critical9.2 | — | 1.0% | May 22, 2026 |
36Monitor | CVE-2025-10263No exploit | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-arm · c1-ultra · CWE-362 | Critical9.1 | — | 0.5% | Jun 9, 2026 |
34Monitor | CVE-2026-31812No exploit | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsingquinn-rs · quinn · CWE-248 | High8.7 | — | 0.9% | Mar 10, 2026 |
34Monitor | CVE-2026-41673No exploit | xmldom: Denial of service via uncontrolled recursion in XML serializationxmldom · xmldom · CWE-674 | High8.7 | — | 0.9% | May 7, 2026 |
34Monitor | CVE-2026-5367No exploit | Ovn: ovn: information disclosure via crafted dhcpv6 packetsred hat · fast datapath for red hat enterprise linux 10 · CWE-130 | High8.6 | — | 0.9% | Apr 24, 2026 |
34Monitor | CVE-2026-35469No exploit | SpdyStream: DOS on CRImoby · spdystream · CWE-770 | High8.7 | — | 0.8% | Apr 16, 2026 |
34Monitor | CVE-2026-12143No exploit | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | High8.7 | — | 0.7% | Jun 12, 2026 |
34Monitor | CVE-2026-41674No exploit | xmldom: XML injection through unvalidated DocumentType serializationxmldom · xmldom · CWE-91 | High8.7 | — | 0.7% | May 7, 2026 |
34Monitor | CVE-2026-41672No exploit | xmldom: XML node injection through unvalidated comment serializationxmldom · xmldom · CWE-91 | High8.7 | — | 0.7% | May 7, 2026 |
34Monitor | CVE-2026-41675No exploit | xmldom: XML node injection through unvalidated processing instruction serializationxmldom · xmldom · CWE-91 | High8.7 | — | 0.6% | May 7, 2026 |
34Monitor | CVE-2026-49851No exploit | Mistune: Potential DoS via quadratic-time parsing in parse_link_textlepture · mistune · CWE-400 | High8.7 | — | 0.6% | Jun 24, 2026 |
34Monitor | CVE-2026-10649No exploit | Pacemaker: pacemaker: denial of service via integer overflow in remote message decompressionred hat · red hat enterprise linux 10 · CWE-190 | High8.6 | — | 0.6% | Jun 16, 2026 |
34Monitor | CVE-2026-41163No exploit | bubblewrap vulnerable to privilege escalation in setuid mode via ptracecontainers · bubblewrap · CWE-269 | High8.7 | — | 0.4% | May 9, 2026 |
33Monitor | CVE-2025-13878No exploit | Malformed BRID/HHIT records can cause named to terminate unexpectedlyisc · bind 9 · CWE-617 | High7.5 | — | 9.2% | Jan 21, 2026 |
33Monitor | CVE-2026-4892No exploit | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code withdnsmasq · dnsmasq · CWE-122 | High8.4 | — | 0.3% | May 11, 2026 |
33Monitor | CVE-2026-54369No exploit | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
33Monitor | CVE-2026-54371No exploit | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrattr project · attr · CWE-59 | High8.4 | — | 0.2% | Jun 29, 2026 |
32Monitor | CVE-2026-41316No exploit | ERB has an @_init deserialization guard bypass via def_module / def_method / def_classruby · erb · CWE-693 | High8.1 | — | 1.3% | Apr 23, 2026 |
31Monitor | CVE-2026-6893No exploit | Dracut: dracut: root code execution via dhcp options command injectionred hat · red hat enterprise linux 10 · CWE-78 | High7.5 | — | 3.1% | Jun 10, 2026 |
31Monitor | CVE-2026-3238No exploit | Samba: denial of service against ad dc wins serverred hat · red hat enterprise linux 10 · CWE-476 | High7.5 | — | 2.0% | Jun 8, 2026 |
31Monitor | CVE-2026-11332No exploit | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-88 | High7.8 | — | 0.2% | Jun 5, 2026 |
31Monitor | CVE-2026-3842No exploit | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writered hat · red hat enterprise linux 10 · CWE-787 | High7.8 | — | 0.2% | Jul 15, 2026 |
31Monitor | CVE-2026-12505No exploit | Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallred hat · red hat enterprise linux 10 · CWE-250 | High7.8 | — | 0.2% | Jun 18, 2026 |
- CVE-2026-2279739Monitor
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1
CriticalCVSS 9.9No exploitEPSS 1%openstack · keystonemiddlewareJan 19, 2026
- CVE-2026-4499037Monitor
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
CriticalCVSS 9.3No exploitEPSS 1%apostrophecms · sanitize-htmlJun 12, 2026
- CVE-2026-927736Monitor
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CriticalCVSS 9.2Proof of conceptEPSS 1%May 22, 2026
- CVE-2025-1026336Monitor
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-
CriticalCVSS 9.1No exploitEPSS 1%arm · c1-ultraJun 9, 2026
- CVE-2026-3181234Monitor
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
HighCVSS 8.7No exploitEPSS 1%quinn-rs · quinnMar 10, 2026
- CVE-2026-4167334Monitor
xmldom: Denial of service via uncontrolled recursion in XML serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-536734Monitor
Ovn: ovn: information disclosure via crafted dhcpv6 packets
HighCVSS 8.6No exploitEPSS 1%red hat · fast datapath for red hat enterprise linux 10Apr 24, 2026
- CVE-2026-3546934Monitor
SpdyStream: DOS on CRI
HighCVSS 8.7No exploitEPSS 1%moby · spdystreamApr 16, 2026
- CVE-2026-1214334Monitor
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
HighCVSS 8.7No exploitEPSS 1%form-data · form-dataJun 12, 2026
- CVE-2026-4167434Monitor
xmldom: XML injection through unvalidated DocumentType serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-4167234Monitor
xmldom: XML node injection through unvalidated comment serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-4167534Monitor
xmldom: XML node injection through unvalidated processing instruction serialization
HighCVSS 8.7No exploitEPSS 1%xmldom · xmldomMay 7, 2026
- CVE-2026-4985134Monitor
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
HighCVSS 8.7No exploitEPSS 1%lepture · mistuneJun 24, 2026
- CVE-2026-1064934Monitor
Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
HighCVSS 8.6No exploitEPSS 1%red hat · red hat enterprise linux 10Jun 16, 2026
- CVE-2026-4116334Monitor
bubblewrap vulnerable to privilege escalation in setuid mode via ptrace
HighCVSS 8.7No exploitEPSS 0%containers · bubblewrapMay 9, 2026
- CVE-2025-1387833Monitor
Malformed BRID/HHIT records can cause named to terminate unexpectedly
HighCVSS 7.5No exploitEPSS 9%isc · bind 9Jan 21, 2026
- CVE-2026-489233Monitor
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with
HighCVSS 8.4No exploitEPSS 0%dnsmasq · dnsmasqMay 11, 2026
- CVE-2026-5436933Monitor
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
HighCVSS 8.4No exploitEPSS 0%acl project · aclJun 29, 2026
- CVE-2026-5437133Monitor
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
HighCVSS 8.4No exploitEPSS 0%attr project · attrJun 29, 2026
- CVE-2026-4131632Monitor
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
HighCVSS 8.1No exploitEPSS 1%ruby · erbApr 23, 2026
- CVE-2026-689331Monitor
Dracut: dracut: root code execution via dhcp options command injection
HighCVSS 7.5No exploitEPSS 3%red hat · red hat enterprise linux 10Jun 10, 2026
- CVE-2026-323831Monitor
Samba: denial of service against ad dc wins server
HighCVSS 7.5No exploitEPSS 2%red hat · red hat enterprise linux 10Jun 8, 2026
- CVE-2026-1133231Monitor
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
HighCVSS 7.8No exploitEPSS 0%red hat · red hat ansible automation platform 2.5 for rhel 8Jun 5, 2026
- CVE-2026-384231Monitor
Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
HighCVSS 7.8No exploitEPSS 0%red hat · red hat enterprise linux 10Jul 15, 2026
- CVE-2026-1250531Monitor
Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
HighCVSS 7.8No exploitEPSS 0%red hat · red hat enterprise linux 10Jun 18, 2026