Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2836 articles · 123542 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-7309
Red Hat · Red Hat OpenShift Container Platform 4

Openshift-controller-manager: openshift container platform: information disclosure via environment variable injection

Description

A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulnerability allows for information disclosure, specifically impacting the confidentiality of build traffic.

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4—

References

  • https://access.redhat.com/security/cve/CVE-2026-7309(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2463451(issue-tracking, x_refsource_REDHAT)

Related News (1 articles)

Tier C
VulDB3h ago
CVE-2026-7309 | Red Hat OpenShift Container Platform 4 Environment Variable LD_PRELOAD/http_proxy information disclosure
→ No new info (linked only)
CVSS 3.14.3 NONE
CISA KEV❌ No
Actively exploited❌ No
CWECWE-426
PublishedApr 28, 2026
Last enriched2h ago
Trending Score20
Source articles1
Independent1
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHPRE-CVE
Multiple Vulnerabilities in Red Hat Products Allow Remote Code Execution, File Manipulation, and Denial of Service
Trending: 26
NONECVE-2025-14831
Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification
Trending: 24
MEDIUMCVE-2025-66286
Webkitgtk: authorization bypass through webpage::send-request signal handler
Trending: 20
NONECVE-2026-6855EXP
Instructlab: instructlab: path traversal allows arbitrary directory creation and file write
Trending: 18
NONECVE-2026-6848
Quay: red hat quay: authentication bypass allows privileged actions without valid credentials
Trending: 16

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 28, 2026
Discovered by ZDM
Apr 28, 2026