Openshift virtualization
This hub aggregates every CVE we track for Openshift virtualization, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
10
CVEs tracked
1
Critical
3
High
1
In CISA KEV
Severity distribution
MEDIUM5HIGH3LOW1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
6
0
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Openshift virtualization.
- CVE-2026-13434Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled4.9
- CVE-2026-13322Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service3.8
- CVE-2026-13318Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip6.4
- CVE-2026-13218Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher4.2
- CVE-2026-13201Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption7.3
- CVE-2026-13208Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body6.5
- CVE-2023-48795The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (fr...5.9
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- CVE-2020-1742An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and ...7.0
- CVE-2020-14316A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful exploitation allows an attacker to assume the privile...9.9
Product normalization is registry-driven with AI assist and human review. How it works