Openshift
154 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Openshift, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Openshift CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 2 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 154 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical11
- High59
- Medium72
- Low12
Latest CVEs
The 15 most recently published vulnerabilities affecting Openshift.
- CVE-2026-35092Corosync: corosync: denial of service via integer overflow in join message validation7.5
- CVE-2026-35091Corosync: corosync: denial of service and information disclosure via crafted udp packet8.2
- CVE-2026-32285Denial of service in github.com/buger/jsonparser7.5
- CVE-2025-61594URI Credential Leakage Bypass over CVE-2025-272217.5
- CVE-2025-14512Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow6.5
- CVE-2024-45777Grub2: grub-core/gettext: integer overflow leads to heap oob write.6.7
- CVE-2024-12085Rsync: info leak via uninitialized stack contents7.5
- CVE-2024-1485Registry-support: decompress can delete files outside scope via relative paths8.0
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.7.5
- CVE-2023-24538Backticks not treated as string delimiters in html/template9.8
- CVE-2023-0229A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they c...6.3
- CVE-2023-0296The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in th...5.3
- CVE-2022-3259Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.7.4
- CVE-2022-3260The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.4.8
- CVE-2022-3262A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name wi...8.1
Product grouping is registry-driven, with AI assist and human review. How it works