See how open policy agent compares to other vendors in security performance
Gatekeeper v3.15.4Gatekeeper is a validating webhook with auditing capabilities that canenforce custom resource definition-based policies that are run with theOpen Policy Agent (OPA). Gatekeeper is supported through a Red Hat AdvancedCluster Management for Kubernetes subscription.Starting in v3.15, the following namespaces are exempt from admission control: kube- multicluster-engine hypershift hive rhacs-operator open-cluster- openshift- To disable the default exempt namespaces, set the namespaces you want on theobject.Security fix(es): golang.org/x/oauth2: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (CVE-2025-22868) golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (CVE-2025-22869) Additional Release Notes: v3.15.0 https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.15.0 v3.15.1 https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.15.1
Gatekeeper Operator v0.2Gatekeeper is an open source project that applies the OPA ConstraintFramework to enforce policies on your Kubernetes clusters. This advisory contains the container images for Gatekeeper that include security updates, and container upgrades.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section. Note: Gatekeeper support from the Red Hat support team is limited caseswhere it is integrated and used with Red Hat Advanced Cluster Managementfor Kubernetes. For support options for any other use, see the Gatekeeperopen source project website at:https://open-policy-agent.github.io/gatekeeper/website/docs/howto/. Security updates: golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565) golang: crypto/elliptic IsOnCurve returns true for invalid field elements (CVE-2022-23806)
Gatekeeper Operator v0.2Gatekeeper is an open source project that applies the OPA ConstraintFramework to enforce policies on your Kubernetes clusters. This advisory contains the container images for Gatekeeper that include bugfixes and container upgrades. Note: Gatekeeper support from the Red Hat support team is limited to where it is integrated and used with Red Hat Advanced Cluster Managementfor Kubernetes. For support options for any other use, see the Gatekeeperopen source project website at:https://open-policy-agent.github.io/gatekeeper/website/docs/howto/. Security fix: CVE-2022-30629: gatekeeper-container: golang: crypto/tls: session tickets lack random ticketageadd CVE-2022-1705: golang: net/http: improper sanitization of Transfer-Encoding header CVE-2022-1962: golang: go/parser: stack exhaustion in all Parse functions CVE-2022-28131: golang: encoding/xml: stack exhaustion in Decoder.Skip CVE-2022-30630: golang: io/fs: stack exhaustion in Glob CVE-2022-30631: golang: compress/gzip: stack exhaustion in Reader.Read CVE-2022-30632: golang: path/filepath: stack exhaustion in Glob CVE-2022-30635: golang: encoding/gob: stack exhaustion in Decoder.Decode CVE-2022-30633 golang: encoding/xml: stack exhaustion in Unmarshal CVE-2022-32148 golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working