Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Moritz Clasmeier

#17161of 55,071
16.2Total CVSS
Vulnerabilities · 2
High
2
PT-2026-66735
8.5
2026-07-31
Red Hat · Red Hat Advanced Cluster Security 4 · CVE-2026-10079
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
PT-2026-55913
7.7
2026-07-06
Red Hat · Red Hat Advanced Cluster Security For Kubernetes · CVE-2026-9165
**Name of the Vulnerable Software and Affected Versions** Red Hat Advanced Cluster Security for Kubernetes (affected versions not specified) **Description** Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.