Red hat openshift container platform 4
This hub aggregates every CVE we track for Red hat openshift container platform 4, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
323
CVEs tracked
9
Critical
113
High
0
In CISA KEV
Severity distribution
MEDIUM170HIGH113LOW31CRITICAL9
Monthly trend
5
7
2
9
16
12
2
6
13
14
4
4
6
8
4
6
7
17
21
18
25
31
29
38
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat openshift container platform 4.
- CVE-2026-75887Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler7.5
- CVE-2026-75886Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding7.2
- CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization5.4
- CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service7.5
- CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator7.7
- CVE-2026-95508Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu7.4
- CVE-2026-75939Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed7.4
- CVE-2026-92574Cri-o: cri-o checkpoint restore bypasses destination security context8.8
- CVE-2026-15801Cri-o: cri-o: insufficient validation during container checkpoint restore8.0
- CVE-2026-75885Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint9.3
- CVE-2026-81627Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram8.2
- CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute5.5
- CVE-2026-42784Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion7.4
- CVE-2025-11395Podman: arbitrary file write when importing oci archive5.5
- CVE-2026-79699Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory4.4
Product normalization is registry-driven with AI assist and human review. How it works