Openshift Serverless

Vendor:

First CVE: Aug 26, 2022 · Active for 3 years

13
Total CVEs
More Total CVEs than 91% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
7.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Openshift Serverless over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2022
3 years ago
Most Recent CVE
Aug 6, 2025
352 days ago

CVE Severity & Scoring

Openshift Serverless13 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (53.8%)
High6 (46.2%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low2 (15.4%)
High1 (7.7%)
None10 (76.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing re
May 14, 20248.327NONO
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of p
Sep 20, 20238.125NONO
It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. Thes
Aug 26, 20227.524NONO
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory
Mar 21, 20247.523NONO
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FI
Jul 5, 20237.523NONO
A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incor
Aug 6, 20253.721NONO
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other Jav
Feb 10, 20255.421NONO
A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions usi
Apr 25, 20246.520NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
1 CVE
7.7% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 97th percentile
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Openshift Serverless

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.018.11.2%00