CVE Tools

Openshift

154 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Openshift, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Openshift CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Openshift CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-021
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-122
2026-010
2026-020
2026-031
2026-042
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 154 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical117%
  • High5938%
  • Medium7247%
  • Low128%

Latest CVEs

The 15 most recently published vulnerabilities affecting Openshift.

  1. CVE-2026-35092Corosync: corosync: denial of service via integer overflow in join message validation7.5
  2. CVE-2026-35091Corosync: corosync: denial of service and information disclosure via crafted udp packet8.2
  3. CVE-2026-32285Denial of service in github.com/buger/jsonparser7.5
  4. CVE-2025-61594URI Credential Leakage Bypass over CVE-2025-272217.5
  5. CVE-2025-14512Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow6.5
  6. CVE-2024-45777Grub2: grub-core/gettext: integer overflow leads to heap oob write.6.7
  7. CVE-2024-12085Rsync: info leak via uninitialized stack contents7.5
  8. CVE-2024-1485Registry-support: decompress can delete files outside scope via relative paths8.0
  9. CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.7.5
  10. CVE-2023-24538Backticks not treated as string delimiters in html/template9.8
  11. CVE-2023-0229A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they c...6.3
  12. CVE-2023-0296The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in th...5.3
  13. CVE-2022-3259Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.7.4
  14. CVE-2022-3260The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.4.8
  15. CVE-2022-3262A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name wi...8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store