CVE Tools

Red Hat Openshift Virtualization 4

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Openshift Virtualization 4, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Openshift Virtualization 4 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Openshift Virtualization 4 CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-082
2025-090
2025-101
2025-110
2025-121
2026-012
2026-020
2026-030
2026-041
2026-051
2026-066
2026-071
2026-081
2026-092

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High832%
  • Medium1560%
  • Low28%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Openshift Virtualization 4.

  1. CVE-2026-79699Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory4.4
  2. CVE-2026-79705Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers4.5
  3. CVE-2026-19730Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives4.2
  4. CVE-2026-17527Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone7.7
  5. CVE-2026-13434Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled4.9
  6. CVE-2026-13322Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service3.8
  7. CVE-2026-13318Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip6.4
  8. CVE-2026-13218Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher4.2
  9. CVE-2026-13208Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body6.5
  10. CVE-2026-13201Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption7.3
  11. CVE-2026-9804Kubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read7.7
  12. CVE-2026-6383Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation5.4
  13. CVE-2025-14525Kubevirt: kubevirt: vm administration denial of service via guest agent6.4
  14. CVE-2025-14459Virt-cdi-controller: unauthorized pvc cloning via dataimportcron8.5
  15. CVE-2025-14946Libnbd: libnbd: arbitrary code execution via ssh argument injection through a malicious uri4.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store