Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
cvss
0.0
medium
severity out of 10
epss
0.00%
low
chance of exploitation in 30 days, 29th percentile of all CVEs
xyz score
0.0
low
CyberXYZ composite out of 10
fig. 01 — CVE-2026-10609, the advisory selected below
// 1 advisories
CVE-2026-10609
MODERATE
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Checked 2026-09-25 at 17:45 UTC. The most recent advisory here was published 2026-06-23. Updated continuously from NVD, GHSA, OSV and CNA feeds.