compliance/openshift-compliance-rhel8-operator vulnerabilities
CVEs whose affected-version data names the compliance/openshift-compliance-rhel8-operator package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-7195Medium· 6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…
▾ Sunlitoperator-framework · operator-sdkEPSS 0.22%via NVD
CVE-2025-7425High· 7.8PoCA flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the pro…
▾ MidnightGNOME · libxml2EPSS 0.42%via NVD