FAIL › dossier
openshift container platform
PRODUCT· dossier confidence 20%
Red Hat OpenShift is a leading container platform with a strong security track record, but its reliance on third-party components like Samba and GnuTLS introduces critical vulnerabilities that require vigilant patching and supply chain monitoring.
PROFILE
Categorycontainer platformWhat they doRed Hat OpenShift is a Kubernetes-based container platform for deploying, managing, and scaling containerized applications.
Websitehttps://www.openshift.com ↗
SECURITY POSTURE
Red Hat OpenShift maintains a mature security posture with active CVE tracking and rapid patching, though its supply chain relies on third-party components like Samba and GnuTLS that occasionally introduce critical vulnerabilities.
Notable failures
- CVE-2026-4408: Samba RCE0day via misconfigured check password script
- CVE-2026-42010: GnuTLS RSA-PSK NUL character username matching flaw
- CVE-2026-33845: GnuTLS DTLS integer underflow via malformed fragments
Patterns: third-party component vulnerabilities; critical RCE0day exploits in supply chain dependencies
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-05-28 | CVE-2026-4408 | critical | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed |
| 2026-05-07 | CVE-2026-42010 | high | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe |
| 2026-04-30 | CVE-2026-33845 | high | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of |
DOSSIER SOURCES
- Red Hat - Overview, News & Similar companies | ZoomInfo.com · www.zoominfo.com
- Red Hat OpenShift - endoflife.date · endoflife.date
- RHSA-2026:54547 - Security Advisory - Red Hat Customer Portal · access.redhat.com
Open questions: What is the founding year of Red Hat OpenShift Container Platform? · What is the headquarters location of Red Hat OpenShift Container Platform? · What is the corporate size of Red Hat OpenShift Container Platform? · What is the ownership structure of Red Hat OpenShift Container Platform? · What is the official website URL for Red Hat OpenShift Container Platform? · Are there any internal failure history events directly related to Red Hat OpenShift Container Platform?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-20 19:10:38.962545+00:00