Known Vulnerabilities for Red Hat OpenShift On AWS by Red Hat
Listed below are 10 of the newest known vulnerabilities associated with "Red Hat OpenShift On AWS" by "Red Hat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86332 json | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource r... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-81320 json | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 ... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-81207 json | IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully ... | Not Provided | 2026-09-10 | 2026-09-11 |
| CVE-2026-78234 json | A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-servi... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-75939 json | A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by ... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-75885 json | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoint... | Not Provided | 2026-09-18 | 2026-09-21 |
| CVE-2026-71567 json | In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without ... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-71474 json | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can... | Not Provided | 2026-08-11 | 2026-09-05 |
| CVE-2026-66788 json | A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the des... | Not Provided | 2026-08-20 | 2026-09-03 |
| CVE-2026-56160 json | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-07-24 | 2026-08-07 |