openshift4/ose-hypershift-rhel9 vulnerabilities
CVEs whose affected-version data names the openshift4/ose-hypershift-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-16242Critical· 9.4A flaw was found in the Konnectivity proxy-server configuration for hosted control planes
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not va…
▾ MidnightRed Hat · multicluster-engine/hypershift-rhel9-operatorEPSS 0.92%via NVD
CVE-2026-33846High· 7.5A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type,…
▾ TwilightRed Hat · gnutlsEPSS 1.1%via NVD