VulnSea

insights-client vulnerabilities

CVEs whose affected-version data names the insights-client package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-71846Medium· 6.5
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.12%via NVD
CVE-2026-71845Medium· 6.3
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to le…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.28%via NVD
CVE-2026-71475Medium· 6.8
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.47%via NVD
CVE-2026-71474High· 7.1
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read t…

Twilightredhat · advanced_cluster_management_for_kubernetesEPSS 0.11%via NVD
insights-client vulnerabilities (CVEs) · VulnSea