Skip to content
COOEY

FAIL › dossier

openshift container platform

PRODUCT

· dossier confidence 20%

Red Hat OpenShift is a leading container platform with a strong security track record, but its reliance on third-party components like Samba and GnuTLS introduces critical vulnerabilities that require vigilant patching and supply chain monitoring.

PROFILE
Categorycontainer platformWhat they doRed Hat OpenShift is a Kubernetes-based container platform for deploying, managing, and scaling containerized applications. Websitehttps://www.openshift.com ↗
SECURITY POSTURE

Red Hat OpenShift maintains a mature security posture with active CVE tracking and rapid patching, though its supply chain relies on third-party components like Samba and GnuTLS that occasionally introduce critical vulnerabilities.

Notable failures
  • CVE-2026-4408: Samba RCE0day via misconfigured check password script
  • CVE-2026-42010: GnuTLS RSA-PSK NUL character username matching flaw
  • CVE-2026-33845: GnuTLS DTLS integer underflow via malformed fragments
Patterns: third-party component vulnerabilities; critical RCE0day exploits in supply chain dependencies
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2026-05-28 CVE-2026-4408 critical A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed
2026-05-07 CVE-2026-42010 high A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe
2026-04-30 CVE-2026-33845 high A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of
Open questions: What is the founding year of Red Hat OpenShift Container Platform? · What is the headquarters location of Red Hat OpenShift Container Platform? · What is the corporate size of Red Hat OpenShift Container Platform? · What is the ownership structure of Red Hat OpenShift Container Platform? · What is the official website URL for Red Hat OpenShift Container Platform? · Are there any internal failure history events directly related to Red Hat OpenShift Container Platform?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-20 19:10:38.962545+00:00