CVE Tools

Red Hat Ceph Storage 8

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Ceph Storage 8, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Ceph Storage 8 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Ceph Storage 8 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-051
2025-060
2025-070
2025-081
2025-090
2025-101
2025-111
2025-123
2026-011
2026-021
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High325%
  • Medium867%
  • Low18%

Latest CVEs

The 12 most recently published vulnerabilities affecting Red Hat Ceph Storage 8.

  1. CVE-2026-18495Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough6.1
  2. CVE-2025-12801Nfs-utils: rpc.mountd in the nfs-utils privilege escalation6.5
  3. CVE-2025-14831Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification5.3
  4. CVE-2025-9820Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function4.0
  5. CVE-2025-14874Nodemailer: nodemailer: denial of service via crafted email address header7.5
  6. CVE-2025-14104Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames6.1
  7. CVE-2025-14010Ansible-collection-community-general: ansible-collection-community-general: keycloak user module leaks credentials in verbose output5.5
  8. CVE-2025-13601Glib: integer overflow in in g_escape_uri_string()7.7
  9. CVE-2025-11561Sssd: sssd default kerberos configuration allows privilege escalation on ad-joined linux systems8.8
  10. CVE-2025-8556Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results3.7
  11. CVE-2025-4598Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump4.7
  12. CVE-2024-11831Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store