Known vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) - page 2

Software CPE: cpe:2.3:a:red_hat:openshift_container_storage:*:*:*:*:*:*:*:*
Total vulnerabilities: 476
Public exploits: 35
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift Data Foundation (formerly OpenShift Container Storage) OpenShift Data Foundation (formerly OpenShift Container Storage) is affected by 476 known vulnerabilities: 1 critical, 90 high, 246 medium, 139 low Critical High Medium Low

Vulnerabilities (476)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132291 - Resource exhaustion
CVE-2026-48779
CWE-400 Medium
No
No
4.18.25, 4.19.20 25.05.2026 SB2026052550
SB2026062253
SB2026062254
and 4 more
#VU128730 - Improper Authorization
CVE-2026-33186
CWE-285 High
No
No
4.16.30, 4.18.24, 4.18.25, 4.19.19, 4.19.20, 4.20.14 01.05.2026 SB2026050106
SB2026050107
SB2026050108
and 69 more
#VU127582 - Allocation of Resources Without Limits or Throttling
CVE-2026-22036
CWE-770 Medium
No
No
4.20.14 24.04.2026 SB20260424138
SB20260424156
SB20260424157
and 6 more
#VU125803 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-4800
CWE-94 High
No
No
4.18.25, 4.19.20 10.04.2026 SB2026041094
SB20260410101
SB20260410102
and 59 more
#VU124772 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-22029
CWE-79 Low
No
No
4.18.24, 4.19.19 01.04.2026 SB2026040154
SB2026040164
SB2026041309
and 10 more
#VU124033 - Improper input validation
CVE-2025-61728
CWE-20 Medium
No
No
4.19.19 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 46 more
#VU118221 - Incorrect Default Permissions
CVE-2025-7195
CWE-276 Low
No
No
4.17.5 10.11.2025 SB2025111053
SB2025120350
SB2025120351
and 8 more
#VU114392 - Improper Handling of Unexpected Data Type
CVE-2025-7339
CWE-241 Low
No
No
4.20.14 22.08.2025 SB2025082222
SB2025091525
SB2025091621
and 18 more
#VU114080 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-47907
CWE-362 Low
No
No
4.18, 4.18.25 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 50 more
#VU112890 - Inefficient Regular Expression Complexity
CVE-2025-5889
CWE-1333 Low
No
No
4.17.5 15.07.2025 SB2025071511
SB2025071512
SB2025071513
and 33 more
#VU105879 - Use After Free
CVE-2024-55549
CWE-416 High
No
No
4.17.7 19.03.2025 SB2025031964
SB2025031965
SB2025032155
and 69 more
#VU105461 - Resource exhaustion
CVE-2025-22868
CWE-400 Medium
No
No
4, 4.15.14, 4.18.3 10.03.2025 SB2025031013
SB2025031015
SB2025031076
and 89 more
#VU102357 - Improper Authentication
CVE-2024-48916
CWE-287 High
No
No
4, 4.14.18, 4.15.14 06.01.2025 SB2025010643
SB2025010644
SB2025010702
and 11 more
#VU96716 - Incorrect Regular Expression
CVE-2024-39249
CWE-185 Medium
No
No
4, 4.14.18, 4.15.14, 4.17.7 03.09.2024 SB2024090325
SB2024090326
SB2024090359
and 20 more
#VU96055 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-42353
CWE-601 Low
No
No
4, 4.14.18, 4.15.14 15.08.2024 SB2024081552
SB2024081555
SB2024081556
and 44 more
#VU89149 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-34069
CWE-94 Medium
No
No
4, 4.14.18, 4.15.14 06.05.2024 SB2024050606
SB2024050723
SB2024050930
and 54 more
#VU84953 - Insufficient Verification of Data Authenticity
CVE-2023-46446
CWE-345 Medium
No
No
4, 4.14.18, 4.15.14 03.01.2024 SB2024010327
SB2024010328
SB2024020802
and 8 more
#VU72340 - Improper input validation
CVE-2023-23934
CWE-20 Low
No
No
4, 4.14.18, 4.15.14 16.02.2023 SB2023021673
SB2023031332
SB2023031613
and 33 more
#VU72339 - Resource exhaustion
CVE-2023-25577
CWE-400 Medium
No
No
4, 4.14.18, 4.15.14 16.02.2023 SB2023021673
SB2023022875
SB2023031332
and 49 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
4.17.5 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more


Showing elements 21 - 40 out of 476