Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Build Of Keycloak MEDIUM 6.5
CVE-2026-16100

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account…

Fix: 26.6.5+
Fix from $1,600 2026-08-05
Hardened Images MEDIUM 5.3
CVE-2026-59848

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing …

No fix yet
Fix from $1,600 2026-07-21
Openshift Service Mesh HIGH 7.5
CVE-2026-47774

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne…

Fix: 1.35.11 / 1.36.7+
Fix from $1,950 2026-06-17
Openshift Container Platform MEDIUM 5.0
CVE-2026-10533

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet…

Mitigation only
Fix from $1,600 2026-06-01
Directory Server HIGH 7.5
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont…

Mitigation only
Fix from $1,950 2026-05-20
Openshift Container Platform MEDIUM 5.5
CVE-2026-4897

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set…

Mitigation only
Fix from $1,600 2026-03-26
Build Of Apache Camel For Spring Boot HIGH 7.5
CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, ref…

Patch available
Fix from $1,950 2025-09-02
Openshift Container Platform MEDIUM 6.5
CVE-2024-50311

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera…

Mitigation only
Fix from $1,600 2024-10-22
Enterprise Linux HIGH 7.5
CVE-2023-50387EPSS 100%

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU…

Patch available
Fix from $1,950 2024-02-14
Openshift Container Platform HIGH 7.5
CVE-2023-6476

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a…

Mitigation only
Fix from $1,950 2024-01-09
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-3171

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources…

Mitigation only
Fix from $1,950 2023-12-27
Keycloak HIGH 7.7
CVE-2023-6563

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline toke…

Fix: 21.0.0+
Fix from $1,950 2023-12-14
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-5379

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error…

Mitigation only
Fix from $1,950 2023-12-12
Openshift Container Platform For Arm64 HIGH 7.5
CVE-2023-5625

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2…

Patch available
Fix from $1,950 2023-11-01
Openshift Container Platform MEDIUM 5.3
CVE-2023-3153

A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a de…

Fix: 22.03.3 / 22.09.2+
Fix from $1,600 2023-10-04
Openshift Api For Data Protection MEDIUM 6.5
CVE-2023-2253

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retu…

Mitigation only
Fix from $1,600 2023-06-06
Integration Camel K HIGH 7.5
CVE-2022-0084

A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. …

Fix: 3.8.7+
Fix from $1,950 2022-08-26
Keycloak HIGH 7.5
CVE-2021-3637

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity …

Fix: 14.0.0+
Fix from $1,950 2021-07-09
Openshift Container Platform MEDIUM 6.5
CVE-2020-14336

A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an atta…

Mitigation only
Fix from $1,600 2021-06-02
Enterprise Linux MEDIUM 5.5
CVE-2021-3527

A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce th…

Fix: after 6.0.0
Fix from $1,600 2021-05-26
Enterprise Linux HIGH 7.5
CVE-2020-25648

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages,…

Fix: 3.58 / 9.2.6.0+
Fix from $1,950 2020-10-20
Keycloak HIGH 7.5
CVE-2020-10758

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak …

Fix: 11.0.1+
Fix from $1,950 2020-09-16
Undertow HIGH 7.5
CVE-2020-10705

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an ou…

Fix: 2.1.1+
Fix from $1,950 2020-06-10
Openshift Service Mesh HIGH 7.5
CVE-2020-8659

CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.

Fix: after 1.13.0
Fix from $1,950 2020-03-04
Enterprise Linux Server Eus HIGH 7.5
CVE-2019-10171

It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would…

Fix: 1.4.0.17+
Fix from $1,950 2019-08-02
Ceph MEDIUM 6.5
CVE-2018-16846

It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16865

An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when m…

Patch available
Fix from $1,950 2019-01-11
Enterprise Linux Desktop HIGH 7.8
CVE-2018-16864

An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a…

Patch available
Fix from $1,950 2019-01-11
Virtualization Host MEDIUM 6.5
CVE-2018-14660

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated…

Fix: after 4.1.4
Fix from $1,600 2018-11-01
Virtualization MEDIUM 6.3
CVE-2018-10908

It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image…

Fix: 4.20.37+
Fix from $1,600 2018-08-09