{"schema_version":1,"title":"Red Hat OpenShift Container Platform 4 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 36 vulnerabilities in Red Hat OpenShift Container Platform 4: 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58216, was published on 30 July 2026.","url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4","json_url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openshift-container-platform-4","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":16,"all_time":36,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":17,"last_365_days":35},"latest":[{"cve":"CVE-2026-58216","cvss":5.3,"slug":"cve-2026-58216-samba-kdc-out-of-bounds-read-in-kpasswd-service","title":"Samba KDC out-of-bounds read in kpasswd service","severity":"medium","exploited":false,"published_at":"2026-07-30T16:17:14.767+00:00","url":"https://junglewise.ai/threats/cve-2026-58216-samba-kdc-out-of-bounds-read-in-kpasswd-service"},{"cve":"CVE-2026-58218","cvss":5.3,"slug":"cve-2026-58218-samba-internal-dns-server-denial-of-service-via-tkey-cache","title":"Samba internal DNS server denial of service via TKEY cache exhaustion","severity":"medium","exploited":false,"published_at":"2026-07-30T14:17:00.307+00:00","url":"https://junglewise.ai/threats/cve-2026-58218-samba-internal-dns-server-denial-of-service-via-tkey-cache"},{"cve":"CVE-2026-16527","cvss":7.3,"slug":"cve-2026-16527-red-hat-pcp-auth-bypass-in-pmproxy-store-endpoint","title":"Red Hat PCP auth bypass in pmproxy /store endpoint","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.813+00:00","url":"https://junglewise.ai/threats/cve-2026-16527-red-hat-pcp-auth-bypass-in-pmproxy-store-endpoint"},{"cve":"CVE-2026-16526","cvss":8.8,"slug":"cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda","title":"Red Hat PCP privilege escalation in linux_sockets PMDA","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.663+00:00","url":"https://junglewise.ai/threats/cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda"},{"cve":"CVE-2026-18107","cvss":7.8,"slug":"cve-2026-18107-criu-privilege-escalation-via-rseq-critical-section-hijack-during","title":"CRIU privilege escalation via rseq critical section hijack during checkpoint","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:32.42+00:00","url":"https://junglewise.ai/threats/cve-2026-18107-criu-privilege-escalation-via-rseq-critical-section-hijack-during"},{"cve":"CVE-2026-49332","cvss":8.5,"slug":"cve-2026-49332-openshift-oauth-proxy-identity-impersonation-via-header-smuggling","title":"OpenShift oauth-proxy identity impersonation via header smuggling","severity":"high","exploited":false,"published_at":"2026-07-28T13:18:46.067+00:00","url":"https://junglewise.ai/threats/cve-2026-49332-openshift-oauth-proxy-identity-impersonation-via-header-smuggling"},{"cve":"CVE-2026-6390","cvss":6.8,"slug":"cve-2026-6390-gnu-nano-format-string-vulnerability-in-multi-buffer-error","title":"GNU nano format string vulnerability in multi-buffer error handling","severity":"medium","exploited":false,"published_at":"2026-07-23T05:16:38.36+00:00","url":"https://junglewise.ai/threats/cve-2026-6390-gnu-nano-format-string-vulnerability-in-multi-buffer-error"},{"cve":"CVE-2026-16517","cvss":2.9,"slug":"cve-2026-16517-libarchive-signed-integer-overflow-in-zip-writer","title":"libarchive signed integer overflow in ZIP writer","severity":"low","exploited":false,"published_at":"2026-07-21T23:17:00.587+00:00","url":"https://junglewise.ai/threats/cve-2026-16517-libarchive-signed-integer-overflow-in-zip-writer"},{"cve":"CVE-2026-16445","cvss":7.5,"slug":"cve-2026-16445-red-hat-dracut-command-injection-via-dhcp-options","title":"Red Hat dracut command injection via DHCP options","severity":"high","exploited":false,"published_at":"2026-07-21T13:17:16.73+00:00","url":"https://junglewise.ai/threats/cve-2026-16445-red-hat-dracut-command-injection-via-dhcp-options"},{"cve":"CVE-2026-16461","cvss":6.5,"slug":"cve-2026-16461-rpcbind-rpcinfo-stack-buffer-overflow-in-rpcbdump","title":"rpcbind rpcinfo stack buffer overflow in rpcbdump","severity":"medium","exploited":false,"published_at":"2026-07-21T12:17:21.03+00:00","url":"https://junglewise.ai/threats/cve-2026-16461-rpcbind-rpcinfo-stack-buffer-overflow-in-rpcbdump"},{"cve":"CVE-2026-15812","cvss":4.8,"slug":"cve-2026-15812-kronosnet-acl-bypass-via-link-id-spoofing-on-unencrypted-dynamic","title":"kronosnet ACL bypass via link ID spoofing on unencrypted dynamic links","severity":"medium","exploited":false,"published_at":"2026-07-21T06:16:28.48+00:00","url":"https://junglewise.ai/threats/cve-2026-15812-kronosnet-acl-bypass-via-link-id-spoofing-on-unencrypted-dynamic"},{"cve":"CVE-2026-15811","cvss":5.8,"slug":"cve-2026-15811-kronosnet-improper-memory-clearing-in-cryptographic-configuration","title":"Kronosnet improper memory clearing in cryptographic configuration","severity":"medium","exploited":false,"published_at":"2026-07-21T06:16:28.343+00:00","url":"https://junglewise.ai/threats/cve-2026-15811-kronosnet-improper-memory-clearing-in-cryptographic-configuration"},{"cve":"CVE-2026-16277","cvss":6.5,"slug":"cve-2026-16277-red-hat-rpcbind-stack-buffer-overflow-in-rpcinfo-utility","title":"Red Hat rpcbind stack buffer overflow in rpcinfo utility","severity":"medium","exploited":false,"published_at":"2026-07-20T15:16:36.72+00:00","url":"https://junglewise.ai/threats/cve-2026-16277-red-hat-rpcbind-stack-buffer-overflow-in-rpcinfo-utility"},{"cve":"CVE-2026-15813","cvss":6.5,"slug":"cve-2026-15813-kronosnet-heap-corruption-in-packet-de-fragmentation-engine","title":"kronosnet heap corruption in packet de-fragmentation engine","severity":"medium","exploited":false,"published_at":"2026-07-20T12:17:55.377+00:00","url":"https://junglewise.ai/threats/cve-2026-15813-kronosnet-heap-corruption-in-packet-de-fragmentation-engine"},{"cve":"CVE-2026-14476","cvss":8,"slug":"cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider","title":"SSSD path traversal in AD GPO provider","severity":"high","exploited":false,"published_at":"2026-07-07T10:16:39.993+00:00","url":"https://junglewise.ai/threats/cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider"},{"cve":"CVE-2026-13757","cvss":6.2,"slug":"cve-2026-13757-p11-kit-stack-exhaustion-via-uncontrolled-recursion-in-rpc","title":"p11-kit stack exhaustion via uncontrolled recursion in RPC attribute parsing","severity":"medium","exploited":false,"published_at":"2026-06-29T19:16:40.907+00:00","url":"https://junglewise.ai/threats/cve-2026-13757-p11-kit-stack-exhaustion-via-uncontrolled-recursion-in-rpc"},{"cve":"CVE-2026-13595","cvss":6.8,"slug":"cve-2026-13595-util-linux-libblkid-heap-use-after-free-in-nested-partition","title":"util-linux libblkid heap use-after-free in nested partition probing","severity":"medium","exploited":false,"published_at":"2026-06-29T09:16:28.303+00:00","url":"https://junglewise.ai/threats/cve-2026-13595-util-linux-libblkid-heap-use-after-free-in-nested-partition"},{"cve":"CVE-2026-55653","cvss":4.3,"slug":"cve-2026-55653-openssh-double-free-in-dh-gex-client-during-fips-validation","title":"OpenSSH double free in DH-GEX client during FIPS validation","severity":"medium","exploited":false,"published_at":"2026-06-23T04:17:36.6+00:00","url":"https://junglewise.ai/threats/cve-2026-55653-openssh-double-free-in-dh-gex-client-during-fips-validation"},{"cve":"CVE-2026-12725","cvss":5.9,"slug":"cve-2026-12725-dnsmasq-heap-buffer-overflow-in-log-query-function","title":"Dnsmasq heap buffer overflow in log_query function","severity":"medium","exploited":false,"published_at":"2026-06-22T16:16:34.49+00:00","url":"https://junglewise.ai/threats/cve-2026-12725-dnsmasq-heap-buffer-overflow-in-log-query-function"},{"cve":"CVE-2026-54100","cvss":8.3,"slug":"cve-2026-54100-red-hat-wmco-improper-ssh-host-key-verification-in-openshift","title":"Red Hat WMCO improper SSH host key verification in OpenShift","severity":"high","exploited":false,"published_at":"2026-06-22T14:17:40.95+00:00","url":"https://junglewise.ai/threats/cve-2026-54100-red-hat-wmco-improper-ssh-host-key-verification-in-openshift"},{"cve":"CVE-2026-54099","cvss":8.8,"slug":"cve-2026-54099-red-hat-wmco-privilege-escalation-in-wicd-csr-auto-approver","title":"Red Hat WMCO privilege escalation in WICD CSR auto-approver","severity":"high","exploited":false,"published_at":"2026-06-22T14:17:40.82+00:00","url":"https://junglewise.ai/threats/cve-2026-54099-red-hat-wmco-privilege-escalation-in-wicd-csr-auto-approver"},{"cve":"CVE-2026-3195","cvss":7.4,"slug":"cve-2026-3195-qemu-heap-overflow-in-virtio-snd-device","title":"QEMU heap overflow in virtio-snd device","severity":"high","exploited":false,"published_at":"2026-06-19T17:16:22.687+00:00","url":"https://junglewise.ai/threats/cve-2026-3195-qemu-heap-overflow-in-virtio-snd-device"},{"cve":"CVE-2026-12505","cvss":7.8,"epss":0.0012,"slug":"cve-2026-12505-samba-cifs-utils-privilege-escalation-in-cifs-upcall","title":"Samba cifs-utils privilege escalation in cifs.upcall","severity":"high","exploited":false,"published_at":"2026-06-18T04:16:44.85+00:00","url":"https://junglewise.ai/threats/cve-2026-12505-samba-cifs-utils-privilege-escalation-in-cifs-upcall"},{"cve":"CVE-2026-44289","cvss":7.5,"epss":0.0068,"slug":"cve-2026-44289-protobufjs-uncontrolled-recursion-in-protobuf-decoding","title":"protobufjs uncontrolled recursion in protobuf decoding","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:55.713+00:00","url":"https://junglewise.ai/threats/cve-2026-44289-protobufjs-uncontrolled-recursion-in-protobuf-decoding"},{"cve":"CVE-2026-43133","cvss":7.9,"epss":0.0012,"slug":"cve-2026-43133-linux-kernel-kvm-incorrect-state-handling-in-nsvm-vmload-vmsave","title":"Linux Kernel KVM incorrect state handling in nSVM VMLOAD/VMSAVE emulation","severity":"high","exploited":false,"published_at":"2026-05-06T12:16:30.48+00:00","url":"https://junglewise.ai/threats/cve-2026-43133-linux-kernel-kvm-incorrect-state-handling-in-nsvm-vmload-vmsave"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"},{"name":"Red Hat AI Inference Server","slug":"ai-inference-server","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ai-inference-server"},{"name":"Red Hat Enterprise Linux 9.0","slug":"enterprise-linux-9-0","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9-0"}],"technology":{"hub":true,"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":[],"category":"platform-as-a-service","homepage":"https://www.redhat.com/en/technologies/cloud-computing/openshift","repo_url":"https://github.com/openshift/origin","description":"A platform-as-a-service based on Kubernetes for deploying and managing containerized applications.","url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},"most_severe":[{"cve":"CVE-2026-16526","cvss":8.8,"slug":"cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda","title":"Red Hat PCP privilege escalation in linux_sockets PMDA","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.663+00:00","url":"https://junglewise.ai/threats/cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda"},{"cve":"CVE-2026-54099","cvss":8.8,"slug":"cve-2026-54099-red-hat-wmco-privilege-escalation-in-wicd-csr-auto-approver","title":"Red Hat WMCO privilege escalation in WICD CSR auto-approver","severity":"high","exploited":false,"published_at":"2026-06-22T14:17:40.82+00:00","url":"https://junglewise.ai/threats/cve-2026-54099-red-hat-wmco-privilege-escalation-in-wicd-csr-auto-approver"},{"cve":"CVE-2026-49332","cvss":8.5,"slug":"cve-2026-49332-openshift-oauth-proxy-identity-impersonation-via-header-smuggling","title":"OpenShift oauth-proxy identity impersonation via header smuggling","severity":"high","exploited":false,"published_at":"2026-07-28T13:18:46.067+00:00","url":"https://junglewise.ai/threats/cve-2026-49332-openshift-oauth-proxy-identity-impersonation-via-header-smuggling"},{"cve":"CVE-2026-54100","cvss":8.3,"slug":"cve-2026-54100-red-hat-wmco-improper-ssh-host-key-verification-in-openshift","title":"Red Hat WMCO improper SSH host key verification in OpenShift","severity":"high","exploited":false,"published_at":"2026-06-22T14:17:40.95+00:00","url":"https://junglewise.ai/threats/cve-2026-54100-red-hat-wmco-improper-ssh-host-key-verification-in-openshift"},{"cve":"CVE-2026-41316","cvss":8.1,"epss":0.0051,"slug":"cve-2026-41316-ruby-erb-arbitrary-code-execution-via-deserialization-guard","title":"Ruby ERB arbitrary code execution via deserialization guard bypass","severity":"high","exploited":false,"published_at":"2026-04-24T03:16:11.897+00:00","url":"https://junglewise.ai/threats/cve-2026-41316-ruby-erb-arbitrary-code-execution-via-deserialization-guard"},{"cve":"CVE-2026-43003","cvss":8,"epss":0.0113,"slug":"cve-2026-43003-openstack-ironic-python-agent-command-injection-via-malicious","title":"OpenStack Ironic Python Agent command injection via malicious image","severity":"high","exploited":false,"published_at":"2026-05-01T09:16:17.44+00:00","url":"https://junglewise.ai/threats/cve-2026-43003-openstack-ironic-python-agent-command-injection-via-malicious"},{"cve":"CVE-2026-14476","cvss":8,"slug":"cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider","title":"SSSD path traversal in AD GPO provider","severity":"high","exploited":false,"published_at":"2026-07-07T10:16:39.993+00:00","url":"https://junglewise.ai/threats/cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider"},{"cve":"CVE-2026-43133","cvss":7.9,"epss":0.0012,"slug":"cve-2026-43133-linux-kernel-kvm-incorrect-state-handling-in-nsvm-vmload-vmsave","title":"Linux Kernel KVM incorrect state handling in nSVM VMLOAD/VMSAVE emulation","severity":"high","exploited":false,"published_at":"2026-05-06T12:16:30.48+00:00","url":"https://junglewise.ai/threats/cve-2026-43133-linux-kernel-kvm-incorrect-state-handling-in-nsvm-vmload-vmsave"},{"cve":"CVE-2026-12505","cvss":7.8,"epss":0.0012,"slug":"cve-2026-12505-samba-cifs-utils-privilege-escalation-in-cifs-upcall","title":"Samba cifs-utils privilege escalation in cifs.upcall","severity":"high","exploited":false,"published_at":"2026-06-18T04:16:44.85+00:00","url":"https://junglewise.ai/threats/cve-2026-12505-samba-cifs-utils-privilege-escalation-in-cifs-upcall"},{"cve":"CVE-2026-18107","cvss":7.8,"slug":"cve-2026-18107-criu-privilege-escalation-via-rseq-critical-section-hijack-during","title":"CRIU privilege escalation via rseq critical section hijack during checkpoint","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:32.42+00:00","url":"https://junglewise.ai/threats/cve-2026-18107-criu-privilege-escalation-via-rseq-critical-section-hijack-during"}],"generated_at":"2026-09-26T11:07:00.153785+00:00"}