CVE-2026-7309
- EPSS 0.03%
- Veröffentlicht 28.04.2026 12:33:55
- Zuletzt bearbeitet 07.05.2026 02:16:00
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantia...
CVE-2026-35092
- EPSS 0.27%
- Veröffentlicht 01.04.2026 13:18:55
- Zuletzt bearbeitet 06.05.2026 21:16:00
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading ...
CVE-2026-35091
- EPSS 0.99%
- Veröffentlicht 01.04.2026 13:18:53
- Zuletzt bearbeitet 13.05.2026 08:16:16
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to a...
CVE-2025-14512
- EPSS 0.07%
- Veröffentlicht 11.12.2025 07:16:00
- Zuletzt bearbeitet 11.05.2026 23:17:18
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribu...
CVE-2025-9566
- EPSS 0.06%
- Veröffentlicht 05.09.2025 19:54:30
- Zuletzt bearbeitet 19.04.2026 20:16:23
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...
CVE-2025-4437
- EPSS 0.06%
- Veröffentlicht 20.08.2025 12:19:18
- Zuletzt bearbeitet 15.04.2026 00:35:42
There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this f...
CVE-2025-6170
- EPSS 0.03%
- Veröffentlicht 16.06.2025 15:24:05
- Zuletzt bearbeitet 19.04.2026 20:16:22
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...
CVE-2025-2586
- EPSS 0.33%
- Veröffentlicht 31.03.2025 12:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead t...
CVE-2024-25132
- EPSS 0.17%
- Veröffentlicht 19.03.2025 17:57:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive ...
CVE-2025-0689
- EPSS 0.08%
- Veröffentlicht 03.03.2025 15:15:16
- Zuletzt bearbeitet 08.01.2026 04:15:52
When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is al...