VYPR

Submariner

by Red Hat

CVEs (2)

  • CVE-2026-66782MedAug 18, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl…

  • CVE-2026-66781MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be…