Known vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes

Software CPE: cpe:2.3:a:red_hat:red_hat_advanced_cluster_security_for_kubernetes:*:*:*:*:*:*:*:*
Total vulnerabilities: 284
Public exploits: 21
Known exploited (KEV): 8
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Red Hat Advanced Cluster Security for Kubernetes Red Hat Advanced Cluster Security for Kubernetes is affected by 284 known vulnerabilities: 3 critical, 52 high, 159 medium, 70 low Critical High Medium Low

Vulnerabilities (284)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140622 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-39822
CWE-59 Low
No
No
4.11.2 31.07.2026 SB2026073128
SB20260731126
SB20260731127
and 8 more
#VU140619 - Resource exhaustion
CVE-2026-42504
CWE-400 Medium
No
No
4.11.2 31.07.2026 SB2026073127
SB20260731138
SB20260731143
and 9 more
#VU136867 - Resource exhaustion
CVE-2026-59869
CWE-400 Medium
No
No
4.11.2 03.07.2026 SB2026070344
SB20260731138
SB2026083174
and 3 more
#VU135820 - Inefficient Algorithmic Complexity
CVE-2026-13149
CWE-407 Medium
No
No
4.11.2 29.06.2026 SB20260629111
SB2026072843
SB2026072877
and 15 more
#VU132386 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-49978
CWE-79 Medium
No
No
4.11.2 27.05.2026 SB2026052785
SB20260731138
SB2026083170
#VU118725 - Resource exhaustion
CVE-2025-9648
CWE-400 Medium
No
No
4.7.9, 4.8.6, 4.9.1 24.11.2025 SB2025112460
SB2025112462
SB2025112463
and 6 more
#VU118141 - Incorrect Default Permissions
CVE-2024-25621
CWE-276 Low
No
No
4.7.9 06.11.2025 SB2025110610
SB2025111276
SB2025112826
and 17 more
#VU115751 - Resource exhaustion
CVE-2025-59375
CWE-400 Medium
No
No
4.7.9, 4.8.7 17.09.2025 SB2025091783
SB2025091789
SB2025091790
and 107 more
#VU114080 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-47907
CWE-362 Low
No
No
4.7.9, 4.8.6 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 50 more
#VU113156 - Memory corruption
CVE-2025-6965
CWE-119 Medium
No
No
4.7.9 22.07.2025 SB2025072254
SB2025072807
SB2025072890
and 100 more
#VU111970 - Expected Behavior Violation
CVE-2025-4435
CWE-440 Low
No
No
4.7.5 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 59 more
#VU111969 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12718
CWE-22 Medium
No
No
4.7.5 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 62 more
#VU111968 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4138
CWE-59 High
Available
No
4.7.5 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 64 more
#VU111967 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4330
CWE-59 High
No
No
4.7.5 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 63 more
#VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4517
CWE-22 High
Available
No
4.7.5 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 77 more
#VU111913 - Integer overflow
CVE-2024-23337
CWE-190 Medium
No
No
4.7.5 25.06.2025 SB2025032035
SB2025070824
SB2025070826
and 29 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
4.7.5 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU101890 - Exposed Dangerous Method or Function
CVE-2024-53920
CWE-749 High
No
No
4.7.5 20.12.2024 SB2024122058
SB2024122059
SB20250226597
and 21 more
#VU81168 - Out-of-bounds read
CVE-2023-40403
CWE-125 Low
No
No
4.7.5 26.09.2023 SB2023092664
SB2023092707
SB2023092143
and 22 more
#VU22494 - Heap-based Buffer Overflow
CVE-2019-17543
CWE-122 High
No
No
4.7.5 04.11.2019 SB2019110405
SB2019102917
SB2019102918
and 12 more


Showing elements 1 - 20 out of 284