Threats Tagged 'cve-2025-68476'
View all threats tagged with 'cve-2025-68476'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-68476'
Click on any threat for detailed analysis and mitigation recommendations
GCVE Database | 03/04/2026, 07:18:30 UTC Added: 05/26/2026, 20:58:12 UTC | |
Release of RHOAI 2.25.2 provides these changes: Join the discussion | GCVE Database | 02/12/2026, 22:43:13 UTC Added: 05/27/2026, 21:14:58 UTC |
0 The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional operator, based on the Kubernetes Event Driven Autoscaler (KEDA), which allows workloads to be scaled using additional metrics sources other than pod metrics. This release is based upon KEDA 2.18.1 Join the discussion | GCVE Database | 02/09/2026, 19:25:55 UTC Added: 06/05/2026, 21:31:54 UTC |
0 KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token specified in spec.hashiCorpVault.credential.serviceAccount. An attacker with permissions to create or modify a TriggerAuthentication resource can exfiltrate the content of any file from the node's filesystem (where the KEDA pod resides) by directing the file's content to a server under their control, as part of the Vault authentication request. The potential impact includes the exfiltration of sensitive system information, such as secrets, keys, or the content of files like /etc/passwd. This issue has been patched in versions 2.17.3 and 2.18.3. Join the discussion | CVE Database V5 | 12/22/2025, 21:35:00 UTC Added: 12/22/2025, 21:59:21 UTC |
Showing 1 to 4 of 4 results