CVE-2026-49332
- EPSS 0.28%
- Veröffentlicht 28.07.2026 12:18:26
- Zuletzt bearbeitet 21.09.2026 17:17:35
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks nor...
CVE-2026-16730
- EPSS 0.11%
- Veröffentlicht 24.07.2026 11:26:18
- Zuletzt bearbeitet 10.09.2026 18:17:56
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connection...
CVE-2026-15813
- EPSS 0.27%
- Veröffentlicht 20.07.2026 10:36:03
- Zuletzt bearbeitet 21.08.2026 13:16:53
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack...
CVE-2026-48914
- EPSS 0.16%
- Veröffentlicht 12.06.2026 09:42:36
- Zuletzt bearbeitet 31.08.2026 18:17:17
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a ma...
CVE-2026-10843
- EPSS 0.33%
- Veröffentlicht 04.06.2026 12:04:49
- Zuletzt bearbeitet 22.07.2026 20:10:00
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-s...
CVE-2026-7309
- EPSS 0.18%
- Veröffentlicht 28.04.2026 12:33:55
- Zuletzt bearbeitet 07.05.2026 02:16:00
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantia...
CVE-2026-35092
- EPSS 0.99%
- Veröffentlicht 01.04.2026 13:18:55
- Zuletzt bearbeitet 21.08.2026 13:17:37
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading ...
CVE-2026-35091
- EPSS 0.87%
- Veröffentlicht 01.04.2026 13:18:53
- Zuletzt bearbeitet 21.08.2026 13:17:36
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to a...
CVE-2025-14512
- EPSS 0.59%
- Veröffentlicht 11.12.2025 07:16:00
- Zuletzt bearbeitet 07.10.2026 11:10:00
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribu...
CVE-2025-9566
- EPSS 1.08%
- Veröffentlicht 05.09.2025 19:54:30
- Zuletzt bearbeitet 28.09.2026 02:17:17
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...