Known Vulnerabilities for Openshift by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Openshift" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71567 json | In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without ... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-71474 json | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can... | Not Provided | 2026-08-11 | 2026-08-12 |
| CVE-2026-66788 json | A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the des... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-56160 json | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-07-24 | 2026-08-07 |
| CVE-2026-54100 json | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH... | Not Provided | 2026-06-22 | 2026-07-29 |
| CVE-2026-54099 json | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-ap... | Not Provided | 2026-06-22 | 2026-07-29 |
| CVE-2026-50237 json | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant... | Not Provided | 2026-08-11 | 2026-08-20 |
| CVE-2026-50236 json | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetc... | Not Provided | 2026-08-11 | 2026-08-19 |
| CVE-2026-49332 json | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forw... | Not Provided | 2026-07-28 | 2026-08-20 |
| CVE-2026-49331 json | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards... | Not Provided | 2026-08-05 | 2026-08-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Openshift | 4.3.5 | |||
| Application | Redhat | Openshift | 4.3 | |||
| Application | Redhat | Openshift | 4.2.21 | |||
| Application | Redhat | Openshift | 4.2 | |||
| Application | Redhat | Openshift | 4.1.37 | |||
| Application | Redhat | Openshift | 4.1 | |||
| Application | Redhat | Openshift | 4.0 | |||
| Application | Redhat | Openshift | 3.9 | |||
| Application | Redhat | Openshift | 3.8 | |||
| Application | Redhat | Openshift | 3.7 | |||
| Application | Redhat | Openshift | 3.6 | |||
| Application | Redhat | Openshift | 3.5 | |||
| Application | Redhat | Openshift | 3.4 | |||
| Application | Redhat | Openshift | 3.3.1.11 | |||
| Application | Redhat | Openshift | 3.3 | |||
| Application | Redhat | Openshift | 3.2.1.23 | |||
| Application | Redhat | Openshift | 3.11.188-4 | |||
| Application | Redhat | Openshift | 3.11 | |||
| Application | Redhat | Openshift | 3.10 | |||
| Application | Redhat | Openshift | 3.1 |