Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat OpenShift Container Platform 4 — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in Red Hat OpenShift Container Platform 4, with AI-generated Chinese analysis, references, and POCs.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-62146 Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket CWE-501 7.8 High 2026-09-30
CVE-2026-75939 Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed CWE-347 7.4 High 2026-09-21
CVE-2026-15801 Cri-o: cri-o: insufficient validation during container checkpoint restore CWE-22 8.0 High 2026-09-21
CVE-2026-49329 Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints CWE-407 7.5 High 2026-09-01
CVE-2026-77176 Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy CWE-73 8.1 High 2026-08-20
CVE-2026-19078 Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing via unvalidated parameter. CWE-601 4.3 Medium 2026-08-11
CVE-2026-49331 Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths CWE-345 6.5 Medium 2026-08-05
CVE-2026-10843 Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws CWE-250 7.2 High 2026-06-04
CVE-2026-10533 Openshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradation CWE-770 5.0 Medium 2026-06-01
CVE-2026-7309 Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection CWE-426 4.3 Medium 2026-04-28
CVE-2025-14443 Ose-openshift-apiserver: openshift api server: server-side request forgery (ssrf) vulnerability in imagestreamimport mechanism CWE-918 6.4 Medium 2025-12-16
CVE-2025-4437 Cri-o: large /etc/passwd file may lead to denial of service CWE-770 5.7 Medium 2025-08-20

All 12 known CVE vulnerabilities affecting Red Hat OpenShift Container Platform 4 with full Chinese analysis, references, and POCs where available.