Redhat Insights-client — known CVE vulnerabilities
Every CVE whose affected-product data names Redhat Insights-client, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (5)
CVE-2023-3972 — CVSS 7.8 (high): A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of…
CVE-2026-71474 — CVSS 7.1 (high): A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the…
CVE-2026-71475 — CVSS 6.8 (medium): A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights…
CVE-2026-71846 — CVSS 6.5 (medium): A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and…
CVE-2026-71845 — CVSS 6.3 (medium): A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including…