Red Hat Openshift Container Platform 4
324 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Red Hat Openshift Container Platform 4, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Openshift Container Platform 4 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 5 |
| 2024-11 | 7 |
| 2024-12 | 2 |
| 2025-01 | 9 |
| 2025-02 | 16 |
| 2025-03 | 12 |
| 2025-04 | 2 |
| 2025-05 | 6 |
| 2025-06 | 13 |
| 2025-07 | 14 |
| 2025-08 | 4 |
| 2025-09 | 4 |
| 2025-10 | 6 |
| 2025-11 | 8 |
| 2025-12 | 4 |
| 2026-01 | 6 |
| 2026-02 | 7 |
| 2026-03 | 17 |
| 2026-04 | 21 |
| 2026-05 | 18 |
| 2026-06 | 25 |
| 2026-07 | 31 |
| 2026-08 | 29 |
| 2026-09 | 39 |
Severity
How the 324 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical9
- High114
- Medium170
- Low31
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Openshift Container Platform 4.
- CVE-2026-93834Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape8.8
- CVE-2026-75887Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler7.5
- CVE-2026-75886Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding7.2
- CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization5.4
- CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service7.5
- CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator7.7
- CVE-2026-95508Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu7.4
- CVE-2026-75939Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed7.4
- CVE-2026-92574Cri-o: cri-o checkpoint restore bypasses destination security context8.8
- CVE-2026-15801Cri-o: cri-o: insufficient validation during container checkpoint restore8.0
- CVE-2026-75885Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint9.3
- CVE-2026-81627Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram8.2
- CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute5.5
- CVE-2026-42784Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion7.4
- CVE-2025-11395Podman: arbitrary file write when importing oci archive5.5
Product grouping is registry-driven, with AI assist and human review. How it works