openshift_update_service vulnerabilities
CVEs whose affected-version data names the openshift_update_service package (pip, rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-72813High· 7.5actix-files: actix-files: Denial of Service via empty Range header in GET requests (CVE-2026-72813)
A flaw was found in actix-files. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by sending a GET request with an empty Range header when the application is configured to abort on panic. This can lead to th…
CVE-2026-72814Medium· 5.3actix-files: actix-files: Information Disclosure via relative path traversal (CVE-2026-72814)
A flaw was found in actix-files. When a non-existing folder is provided as the `serve_from` argument to `Files::new()`, the service incorrectly resolves request paths as relative to the application's working directory. This allows an attac…
CVE-2026-54876High· 7.5⚖ disputedIssue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…
CVE-2026-43871High· 7.5thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)
A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…