Openshift Serverless
Red Hat · 10 CVEs
Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction
Oct 7, 2026
Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results
Aug 6, 2025
Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript
Feb 10, 2025
Cert-manager: potential dos when parsing specially crafted pem inputs
Dec 12, 2024
Golang-fips: golang fips zeroed buffer
Oct 1, 2024
Undertow: learningpushhandler can lead to remote memory dos attacks
Jul 8, 2024
Containers/image: digest type does not guarantee valid type
May 9, 2024
Quarkus: authorization flaw in quarkus resteasy reactive and classic when "quarkus.security.jaxrs.deny-unannotated-endp…
Apr 25, 2024
Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads
Mar 21, 2024
ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
Dec 18, 2023
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
Oct 10, 2023
Quarkus: http security policy bypass
Sep 20, 2023
Ocp & fips mode
Jul 5, 2023
serverless: incomplete fix for CVE-2021-27918 / CVE-2021-31525 / CVE-2021-33196
Aug 26, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-107174 | Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction | MEDIUM | n/a | Oct 7, 2026 |
| CVE-2025-8556 | Github.com/cloudflare/circl: circl-fourq: missing and wrong validation can lead to incorrect results | LOW | 0.51% | Aug 6, 2025 |
| CVE-2024-11831 | Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript | MEDIUM | 1.12% | Feb 10, 2025 |
| CVE-2024-12401 | Cert-manager: potential dos when parsing specially crafted pem inputs | MEDIUM | 0.67% | Dec 12, 2024 |
| CVE-2024-9355 | Golang-fips: golang fips zeroed buffer | HIGH | 0.30% | Oct 1, 2024 |
| CVE-2024-3653 | Undertow: learningpushhandler can lead to remote memory dos attacks | MEDIUM | 1.87% | Jul 8, 2024 |
| CVE-2024-3727 | Containers/image: digest type does not guarantee valid type | HIGH | 1.28% | May 9, 2024 |
| CVE-2023-5675 | Quarkus: authorization flaw in quarkus resteasy reactive and classic when "quarkus.security.jaxrs.deny-unannotated-endpoints" or "quarkus.security.jaxrs.defaul… | MEDIUM | 0.46% | Apr 25, 2024 |
| CVE-2024-1394 | Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads | HIGH | 1.53% | Mar 21, 2024 |
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 93.55% | Dec 18, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 100.00% | Oct 10, 2023 |
| CVE-2023-4853 | Quarkus: http security policy bypass | HIGH | 1.45% | Sep 20, 2023 |
| CVE-2023-3089 | Ocp & fips mode | HIGH | 0.52% | Jul 5, 2023 |
| CVE-2021-3703 | serverless: incomplete fix for CVE-2021-27918 / CVE-2021-31525 / CVE-2021-33196 | HIGH | 0.82% | Aug 26, 2022 |
Showing 1 to 10 of 10 CVEs