CVE-2026-54099
- EPSS 0.11%
- Veröffentlicht 22.06.2026 12:46:04
- Zuletzt bearbeitet 09.09.2026 13:20:30
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additiona...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 11.09.2026 13:18:08
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...
CVE-2026-1784
- EPSS 0.19%
- Veröffentlicht 02.06.2026 07:22:26
- Zuletzt bearbeitet 01.10.2026 17:17:22
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injectio...
- EPSS 0.23%
- Veröffentlicht 01.06.2026 13:19:29
- Zuletzt bearbeitet 22.07.2026 07:10:00
A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit ...
CVE-2026-42965
- EPSS 0.26%
- Veröffentlicht 29.05.2026 09:50:44
- Zuletzt bearbeitet 01.10.2026 17:17:24
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allow...
CVE-2026-46579
- EPSS 0.35%
- Veröffentlicht 29.05.2026 09:50:44
- Zuletzt bearbeitet 10.09.2026 13:20:19
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP req...
CVE-2026-4408
- EPSS 2.5%
- Veröffentlicht 28.05.2026 07:25:27
- Zuletzt bearbeitet 18.09.2026 13:18:31
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client...
CVE-2026-1933
- EPSS 0.86%
- Veröffentlicht 27.05.2026 12:28:44
- Zuletzt bearbeitet 18.09.2026 13:17:25
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point m...
CVE-2026-2340
- EPSS 0.94%
- Veröffentlicht 27.05.2026 12:09:32
- Zuletzt bearbeitet 01.10.2026 18:17:17
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an...
CVE-2026-3012
- EPSS 0.26%
- Veröffentlicht 27.05.2026 10:02:21
- Zuletzt bearbeitet 01.10.2026 17:17:23
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without prop...