CVE Tools

Red Hat Openshift Container Platform

191 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Red Hat Openshift Container Platform, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Openshift Container Platform CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Openshift Container Platform CVEs per month
MonthCVEs
2024-104
2024-114
2024-124
2025-0111
2025-0215
2025-032
2025-043
2025-056
2025-0610
2025-078
2025-081
2025-093
2025-104
2025-1110
2025-122
2026-012
2026-021
2026-0313
2026-0411
2026-052
2026-060
2026-070
2026-080
2026-090

Severity

How the 191 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical116%
  • High6836%
  • Medium9550%
  • Low179%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Openshift Container Platform.

  1. CVE-2026-46300net: skbuff: preserve shared-frag marker during coalescing7.8
  2. CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb frags8.8
  3. CVE-2026-3832Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response3.7
  4. CVE-2026-3833Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison6.5
  5. CVE-2026-33812Excessive memory allocation when decoding malicious SFNT in golang.org/x/image6.1
  6. CVE-2026-5807Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations7.5
  7. CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
  8. CVE-2026-32281Inefficient policy validation in crypto/x5097.5
  9. CVE-2026-27140Code execution vulnerability in SWIG code generation in cmd/go8.8
  10. CVE-2026-33810Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x5098.2
  11. CVE-2026-32282TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix6.4
  12. CVE-2026-39316CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer4.0
  13. CVE-2026-35536In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.7.2
  14. CVE-2026-4046iconv crash due to assertion failure with untrusted input7.5
  15. CVE-2026-5121Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store