VendorsRed Hatopenshift_container_platformall versions
Vulnerabilities

Red Hat OpenShift Container Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

326CVEs
CVE-2025-13601
Glib: integer overflow in in g_escape_uri_string()
Published 2025-11-26 · Modified
7.7EPSS 0.003
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2021-4104
Deserialization of untrusted data in JMSAppender in Apache Log4j 1.2
Published 2021-12-14 · Modified
7.5EPSS 0.806
CVE-2019-11253
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Published 2019-10-17 · Analyzed
7.5EPSS 0.259
CVE-2022-0711
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
Published 2022-03-02 · Modified
7.5EPSS 0.166
CVE-2018-12023
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
Published 2019-03-17 · Modified
7.5EPSS 0.089
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2018-12115
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position of a buffer cause a miscalculation of the maximum length of the input bytes to be written.
Published 2018-08-21 · Modified
7.5EPSS 0.080
CVE-2018-12022
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
Published 2019-03-17 · Modified
7.5EPSS 0.072
CVE-2018-20103
An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
Published 2018-12-12 · Modified
7.5EPSS 0.066
CVE-2019-16276
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
Published 2019-09-30 · Modified
7.5EPSS 0.053
CVE-2020-8945
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
Published 2020-02-12 · Modified
7.5EPSS 0.051
CVE-2024-12088
Rsync: --safe-links option bypass leads to path traversal
Published 2025-01-14 · Modified
7.5EPSS 0.047
CVE-2024-1635
Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol
Published 2024-02-19 · Modified
7.5EPSS 0.046
CVE-2018-20615
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
Published 2019-03-18 · Modified
7.5EPSS 0.045
CVE-2019-2602
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published 2019-04-23 · Modified
7.5EPSS 0.044
CVE-2019-16884
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
Published 2019-09-25 · Modified
7.5EPSS 0.044
CVE-2018-20102
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.
Published 2018-12-12 · Modified
7.5EPSS 0.043
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Published 2021-03-18 · Modified
7.5EPSS 0.032
CVE-2018-14645
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
Published 2018-09-21 · Modified
7.5EPSS 0.030
CVE-2021-20270
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
Published 2021-03-23 · Modified
7.5EPSS 0.028
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2022-27650
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.013
CVE-2025-7424
Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes
Published 2025-07-10 · Modified
7.5EPSS 0.012
CVE-2026-42009
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
Published 2026-05-18 · Modified
7.5EPSS 0.011
CVE-2026-4424
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
Published 2026-03-19 · Modified
7.5EPSS 0.011
CVE-2020-10752
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
Published 2020-06-12 · Modified
7.5EPSS 0.011
CVE-2026-6732
Libxml2: libxml2: denial of service via crafted xsd-validated document
Published 2026-04-23 · Analyzed
7.5EPSS 0.009
CVE-2023-6476
Cri-o: pods are able to break out of resource confinement on cgroupv2
Published 2024-01-09 · Modified
7.5EPSS 0.009
CVE-2018-1070
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
Published 2018-06-12 · Modified
7.5EPSS 0.009
CVE-2024-5037
Openshift/telemeter: iss check during jwt authentication can be bypassed
Published 2024-06-05 · Modified
7.5EPSS 0.008
CVE-2019-3818
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.
Published 2019-02-05 · Modified
7.5EPSS 0.007
CVE-2026-46579
Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend
Published 2026-05-29 · Modified
7.5EPSS 0.006
CVE-2023-3089
Ocp & fips mode
Published 2023-07-05 · Modified
7.5EPSS 0.005
CVE-2022-3248
Openshift api admission checks does not enforce "custom-host" permissions
Published 2023-10-05 · Modified
7.5EPSS 0.004
CVE-2021-20218
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system availability. This has been fixed in kubernetes-client-4.13.2 kubernetes-client-5.0.2 kubernetes-client-4.11.2 kubernetes-client-4.7.2
Published 2021-03-16 · Modified
7.4EPSS 0.013
CVE-2026-3833
Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
Published 2026-04-30 · Modified
7.4EPSS 0.009
← Prev4 / 9Next →