PatchSiren

openshift-metal3 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH openshift-metal3 CVE published 2026-08-17

CVE-2026-71567

The openshift-metal3/fakefish project is affected by a vulnerability where scripts inject shell variables without proper quoting, potentially allowing command injection attacks. This vulnerability, tracked as CVE-2026-71567, has a CVSS score of 7.7 and is classified as HIGH severity. The vulnerability primarily affects Image URL and BMC credentials configurations. Organizations should review their configu [truncated]

CRITICAL openshift-metal3 CVE published 2026-08-17

CVE-2026-71566

CVE-2026-71566 is a critical vulnerability in FakeFish, allowing unauthorized control of VMs by passing incoming credentials to scripts. This works because, ultimately, it's up to the BMC to validate them for real hardware. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. The vulnerability has a CVSS score of 9.3 and is considered critical. Use [truncated]