Red Hat Storage
50 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Red Hat Storage, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Storage CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 2 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 50 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical9
- High19
- Medium19
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Storage.
- CVE-2025-0426A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by...6.2
- CVE-2025-22865ParsePKCS1PrivateKey panic with partial keys in crypto/x5097.5
- CVE-2025-0306Ruby: openssl: ruby marvin attack7.4
- CVE-2024-11236Integer overflow in the firebird and dblib quoters causing OOB writes9.8
- CVE-2024-21510Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redire...5.4
- CVE-2024-10452Organization admins can delete pending invites created in an organization they are not part of.2.2
- CVE-2024-24790Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip9.8
- CVE-2024-35176REXML contains a denial of service vulnerability5.3
- CVE-2024-1135HTTP Request Smuggling in benoitc/gunicorn7.5
- CVE-2024-24784Comments in display names are incorrectly handled in net/mail7.5
- CVE-2024-21490This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super...7.5
- CVE-2023-42669Samba: "rpcecho" development server allows denial of service via sleep() call on ad dc6.5
- CVE-2023-3961Samba: smbd allows client access to unix domain sockets on the file system as root9.1
- CVE-2023-4091Samba: smb clients can truncate files with read-only permissions6.5
- CVE-2023-43665In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial o...7.5
Product grouping is registry-driven, with AI assist and human review. How it works