Openshift Container Platform
478 CVEs tracked. 11 of them are in CISA KEV.
This hub aggregates every CVE we track for Openshift Container Platform, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Openshift Container Platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 6 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 3 |
| 2025-02 | 1 |
| 2025-03 | 3 |
| 2025-04 | 2 |
| 2025-05 | 1 |
| 2025-06 | 8 |
| 2025-07 | 12 |
| 2025-08 | 0 |
| 2025-09 | 2 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 4 |
| 2026-01 | 11 |
| 2026-02 | 5 |
| 2026-03 | 17 |
| 2026-04 | 19 |
| 2026-05 | 14 |
| 2026-06 | 9 |
| 2026-07 | 0 |
| 2026-08 | 11 |
| 2026-09 | 0 |
Severity
How the 478 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical73
- High187
- Medium194
- Low24
Latest CVEs
The 15 most recently published vulnerabilities affecting Openshift Container Platform.
- CVE-2026-13002Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing4.4
- CVE-2026-19617Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser5.5
- CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing5.5
- CVE-2026-71227Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return5.1
- CVE-2026-71226Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path7.3
- CVE-2026-71225Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries6.5
- CVE-2026-68743Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v15.5
- CVE-2026-68744Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply3.3
- CVE-2026-18477Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape4.4
- CVE-2026-18508Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite4.4
- CVE-2026-68742Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr5.5
- CVE-2026-13757P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing6.2
- CVE-2026-13595Util-linux: util-linux: heap use-after-free in libblkid nested partition probing6.8
- CVE-2026-55653Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service4.3
- CVE-2026-12725Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies5.9
Product grouping is registry-driven, with AI assist and human review. How it works