Skip to main content

Threats Tagged 'cve-2026-49332'

View all threats tagged with 'cve-2026-49332'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-49332

Threats Tagged 'cve-2026-49332'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:60023 Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption (CVE-2025-68121) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

The 1.5.2 release of COO.

Join the discussion

CVE-2026-44486 is an information disclosure vulnerability in the Axios Node.js HTTP adapter used by Red Hat OpenShift Container Platform. When Axios is configured to use an authenticated proxy and follows an HTTP redirect, it may inadvertently send the Proxy-Authorization header containing sensitive proxy credentials to the redirected target. This can expose proxy credentials to unintended remote servers. The vulnerability affects Red Hat OpenShift Container Platform versions 4.12 up to but not including 4.13, and 4.14 up to but not including 4.14.71. No effective mitigation or patch meeting Red Hat's criteria is currently available, so users are advised to monitor vendor updates and apply fixes when released.

Join the discussion

Red Hat build of MicroShift is Red Hat's light-weight Kubernetes orchestration solution designed for edge device deployments and is built from the edge capabilities of Red Hat OpenShift Container Platform. MicroShift is an application that is deployed on top of Red Hat Enterprise Linux devices at the edge, providing an efficient way to operate single-node clusters in these low-resource environments. This advisory contains the RPM packages for Red Hat build of MicroShift 4.19.42. Read the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:51007 Security Fix(es): * Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code (CVE-2026-35469) All Red Hat build of MicroShift 4.19 users are advised to use these updated packages and images when they are available in the RPM repository.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.9. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:51036 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/

Join the discussion

A vulnerability in Red Hat OpenShift Container Platform's oauth-proxy component allows an authenticated low-privilege user to impersonate another identity by exploiting header normalization differences in WSGI and PHP frameworks. The proxy sets authenticated identity headers using dash-variant keys but does not remove underscore-variant keys, which are normalized to the same variable upstream. This can lead to identity smuggling and potential impersonation. Red Hat has released OpenShift Container Platform 4.21.28 with fixes addressing this issue.

Join the discussion

CVE-2026-49332 is a security vulnerability in Red Hat OpenShift Container Platform 4.12 related to openshift/oauth-proxy. The proxy sets authenticated identity headers using dash-variant keys but does not remove underscore-variant keys from incoming requests. This discrepancy allows certain web frameworks to normalize these headers to the same variable, enabling an authenticated low-privilege user to forge an identity that may override the legitimate authenticated identity in upstream applications. Red Hat has released security updates for OpenShift Container Platform versions 4.18.52 and 4.19.42 to address this issue.

Join the discussion

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Tag: cve-2026-49332
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses