CVE-2025-14459: Red Hat Openshift Virtualization 4

High severity, CVSS 8.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.

Affected products

  • Red Hat Red Hat Openshift Virtualization 4
  • Red Hat Rhel-9-Cnv-4.19: before v4.19.17-5 (fixed in v4.19.17-5); before v4.19.17-4 (fixed in v4.19.17-4); before v4.19.17-3 (fixed in v4.19.17-3); before v4.19.17.rhel9-82 (fixed in v4.19.17.rhel9-82); before v4.19.17-7 (fixed in v4.19.17-7); before v4.19.17-6 (fixed in v4.19.17-6); …

Published 2026-01-26. Last modified 2026-07-15.