VulnSea

rhbac-4/hawtio-rhel9 vulnerabilities

CVEs whose affected-version data names the rhbac-4/hawtio-rhel9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-81320Medium· 5.5
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and wri…

▾ SunlitRed Hat · rhbac-4/hawtio-rhel9EPSS 0.19%via NVD
CVE-2026-81303Medium· 6.3
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without valida…

▾ SunlitRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.49%via NVD
CVE-2026-80219High· 8.7
2w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.23%via NVD
CVE-2026-78234Critical· 9.9
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author o…

▾ MidnightRed Hat · rhbac-4/hawtio-gateway-rhel9EPSS 0.39%via NVD
CVE-2026-77968High· 8.2
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the Ser…

▾ TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.42%via NVD
rhbac-4/hawtio-rhel9 vulnerabilities (CVEs) · VulnSea