VYPR

Hawtio Operator

by Hawt

CVEs (3)

  • CVE-2026-77968HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access…

  • CVE-2026-81303MedSep 15, 2026
    risk 0.41cvss 6.3epss

    A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace…

  • CVE-2026-81320MedSep 15, 2026
    risk 0.36cvss 5.5epss

    A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard…