Redhat Openshift Update Service — known CVE vulnerabilities
Every CVE whose affected-product data names Redhat Openshift Update Service, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (8)
CVE-2026-74243 — CVSS 6.5 (medium): A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send…
CVE-2025-57854 — CVSS 6.4 (medium): A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd…
CVE-2026-74244 — CVSS 5.9 (medium): A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing…
CVE-2026-74245 — CVSS 5.9 (medium): A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action…
CVE-2026-74240 — CVSS 5.4 (medium): A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication…
CVE-2026-74242 — CVSS 5.3 (medium): A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique…
CVE-2026-74241 — CVSS 4.8 (medium): A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is…
CVE-2026-74247 — CVSS 4.2 (medium): A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request…