Known Vulnerabilities for Openshift by Redhat

Listed below are 10 of the newest known vulnerabilities associated with "Openshift" by "Redhat".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-86332 json A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource r... Not Provided 2026-09-07 2026-09-08
CVE-2026-86330 json An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component... Not Provided 2026-09-28 2026-09-30
CVE-2026-81320 json A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 ... Not Provided 2026-09-15 2026-09-17
CVE-2026-81207 json IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully ... Not Provided 2026-09-10 2026-09-11
CVE-2026-78234 json A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-servi... Not Provided 2026-09-08 2026-09-08
CVE-2026-75939 json A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by ... Not Provided 2026-09-21 2026-09-24
CVE-2026-75887 json A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipula... Not Provided 2026-09-23 2026-10-01
CVE-2026-75886 json A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandl... Not Provided 2026-09-23 2026-10-01
CVE-2026-75885 json A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoint... Not Provided 2026-09-18 2026-10-01
CVE-2026-75884 json A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automou... Not Provided 2026-09-23 2026-09-24

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationRedhatOpenshift4.3.5
ApplicationRedhatOpenshift4.3
ApplicationRedhatOpenshift4.2.21
ApplicationRedhatOpenshift4.2
ApplicationRedhatOpenshift4.1.37
ApplicationRedhatOpenshift4.1
ApplicationRedhatOpenshift4.0
ApplicationRedhatOpenshift3.9
ApplicationRedhatOpenshift3.8
ApplicationRedhatOpenshift3.7
ApplicationRedhatOpenshift3.6
ApplicationRedhatOpenshift3.5
ApplicationRedhatOpenshift3.4
ApplicationRedhatOpenshift3.3.1.11
ApplicationRedhatOpenshift3.3
ApplicationRedhatOpenshift3.2.1.23
ApplicationRedhatOpenshift3.11.188-4
ApplicationRedhatOpenshift3.11
ApplicationRedhatOpenshift3.10
ApplicationRedhatOpenshift3.1

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report