Openshift container platform
This hub aggregates every CVE we track for Openshift container platform, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
478
CVEs tracked
73
Critical
187
High
11
In CISA KEV
Severity distribution
MEDIUM194HIGH187CRITICAL73LOW24
Monthly trend
6
1
0
3
1
3
2
1
8
12
0
2
0
1
4
11
5
17
19
14
9
0
11
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Openshift container platform.
- CVE-2026-13002Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing4.4
- CVE-2026-19617Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser5.5
- CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing5.5
- CVE-2026-71227Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return5.1
- CVE-2026-71226Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path7.3
- CVE-2026-71225Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries6.5
- CVE-2026-68743Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v15.5
- CVE-2026-68744Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply3.3
- CVE-2026-18477Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape4.4
- CVE-2026-18508Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite4.4
- CVE-2026-68742Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr5.5
- CVE-2026-13757P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing6.2
- CVE-2026-13595Util-linux: util-linux: heap use-after-free in libblkid nested partition probing6.8
- CVE-2026-55653Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service4.3
- CVE-2026-12725Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies5.9
Product normalization is registry-driven with AI assist and human review. How it works