Skip to content
Red HatCVE-2026-14251

Red Hat OpenShift GitOps: denial of service

High7.7CVE-2026-14251 · Published Jul 15, 2026 · updated Jul 16, 2026

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift GitOps
Product
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Red Hat advisories

All Red Hat
Advisory
Red Hat AAP Gateway Envoy proxy configuration: authentication bypass by spoofing
High8.2Jul 15
Red Hat samba: denial of service
Medium6.1Jul 15
Red Hat CRI-O: format string
High7.8Jul 15
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.