Known Vulnerabilities for Operator-sdk by Operator-framework
Listed below are 10 of the newest known vulnerabilities associated with "Operator-sdk" by "Operator-framework".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-85694 json | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-85625 json | sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-85594 json | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/servic... | Not Provided | 2026-09-04 | 2026-09-04 |
| CVE-2026-85452 json | MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and ... | Not Provided | 2026-09-03 | 2026-09-04 |
| CVE-2026-85449 json | MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowin... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85441 json | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unau... | Not Provided | 2026-09-03 | 2026-09-04 |
| CVE-2026-85439 json | MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() ... | Not Provided | 2026-09-03 | 2026-09-05 |
| CVE-2026-85156 json | WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view ... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85092 json | LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-84377 json | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, an... | Not Provided | 2026-09-02 | 2026-09-03 |