- EPSS 0.23%
- Veröffentlicht 01.06.2026 13:19:29
- Zuletzt bearbeitet 22.07.2026 07:10:00
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit ...
CVE-2026-42965
- EPSS 0.26%
- Veröffentlicht 29.05.2026 09:50:44
- Zuletzt bearbeitet 24.08.2026 13:18:45
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allow...
CVE-2026-46579
- EPSS 0.35%
- Veröffentlicht 29.05.2026 09:50:44
- Zuletzt bearbeitet 24.08.2026 13:19:00
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP req...
CVE-2026-4408
- EPSS 2.5%
- Veröffentlicht 28.05.2026 07:25:27
- Zuletzt bearbeitet 24.08.2026 13:19:04
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client...
CVE-2026-1933
- EPSS 0.86%
- Veröffentlicht 27.05.2026 12:28:44
- Zuletzt bearbeitet 24.08.2026 13:17:27
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point m...
CVE-2026-2340
- EPSS 0.94%
- Veröffentlicht 27.05.2026 12:09:32
- Zuletzt bearbeitet 21.08.2026 12:16:26
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an...
CVE-2026-3012
- EPSS 0.26%
- Veröffentlicht 27.05.2026 10:02:21
- Zuletzt bearbeitet 21.08.2026 12:16:26
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without prop...
CVE-2026-48864
- EPSS 0.23%
- Veröffentlicht 26.05.2026 16:16:07
- Zuletzt bearbeitet 24.08.2026 12:16:52
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, ...
CVE-2026-4480
- EPSS 13.93%
- Veröffentlicht 26.05.2026 13:56:32
- Zuletzt bearbeitet 24.08.2026 13:19:05
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remot...
CVE-2026-9149
- EPSS 0.31%
- Veröffentlicht 20.05.2026 23:34:56
- Zuletzt bearbeitet 31.07.2026 18:17:37
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...