Skip to content
Threat Feed

Product

OpenShift

5 briefs RSS
critical advisory

Unauthenticated SSRF and DoS in OpenShift Console

An unauthenticated vulnerability in the OpenShift console /api/devfile/ endpoints allows remote attackers to perform Server-Side Request Forgery (SSRF) and cause Denial of Service (DoS) via memory exhaustion.

OpenShift vulnerability cloud web-application path-traversal
1r 2t 1c updated
high advisory

CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation

A flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.

CRIU +3 container-security privilege-escalation linux cloud-native
1t 1c
high advisory

CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool

A privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.

OpenShift +1 privilege-escalation vulnerability red-hat kubernetes cloud-native
1t 1c
critical advisory

KubeVirt virt-handler Symlink Vulnerability Leading to Container Escape (CVE-2026-7374)

CVE-2026-7374 allows an authenticated OpenShift user with edit permissions in a single namespace to escalate privileges to full cluster control by exploiting improper symlink validation in KubeVirt's virt-handler component when connecting to VM console sockets.

virt-handler +1 kubeVirt openshift symlink container escape privilege escalation
2r 1t 1c
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux and OpenShift Grafana Component

A remote anonymous attacker can exploit multiple vulnerabilities in the Grafana component of Red Hat Enterprise Linux and OpenShift to execute arbitrary code, disclose confidential information, and cause a denial-of-service condition.

Red Hat Enterprise Linux +1 grafana rhel openshift vulnerability code execution information disclosure denial of service
2r 3t