Red Hat
300 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-73267
HIGH 7.7
Multicluster Engine For Kubernetes — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standar…
2026-08-21
CVE-2026-11861
CRITICAL 9.6
Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Act…
2026-08-20
CVE-2026-13097
CRITICAL 9.1
Red Hat Enterprise Linux 10 — A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal nam…
2026-08-20
CVE-2026-18917
HIGH 7.8
Red Hat Enterprise Linux 10 — A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the…
2026-08-20
CVE-2026-19582
HIGH 7.8
Migration Toolkit For Containers — In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbit…
2026-08-20
CVE-2026-19611
HIGH 7.4
Red Hat Build Of Apache Camel 4 For Quarkus 3 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, whic…
2026-08-20
CVE-2026-66785
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traf…
2026-08-20
CVE-2026-66787
HIGH 8.7
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulne…
2026-08-20
CVE-2026-66788
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerabilit…
2026-08-20
CVE-2026-67567
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who h…
2026-08-20
CVE-2026-73137
HIGH 7.7
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RH…
2026-08-20
CVE-2026-73196
MEDIUM 4.3
Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting a…
2026-08-20
CVE-2026-73197
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending over…
2026-08-20
CVE-2026-73198
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_…
2026-08-20
CVE-2026-73199
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointe…● PoC
2026-08-20
CVE-2026-77014
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-me…
2026-08-20
CVE-2026-77176
HIGH 8.1
Red Hat Openshift Container Platform 4 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest p…
2026-08-20
CVE-2026-18874
MEDIUM 6.2
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (…
2026-08-19
CVE-2026-43961
HIGH 7.8
Vim — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragment…
2026-08-19
CVE-2026-66794
CRITICAL 9.3
Multicluster Engine For Kubernetes — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerabil…
2026-08-19
CVE-2026-70496
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster adm…
2026-08-19
CVE-2026-71470
CRITICAL 9.1
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom…
2026-08-19
CVE-2026-75569
HIGH 7.7
Multicluster Engine For Kubernetes — A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote reposito…
2026-08-19
CVE-2026-75900
MEDIUM 6.1
Red Hat Enterprise Linux 10 — An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard c…
2026-08-19
CVE-2026-76139
HIGH 8
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from…
2026-08-19
CVE-2026-76166
MEDIUM 4.3
Red Hat Jboss Enterprise Application Platform 7 — A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted U…
2026-08-19
CVE-2026-76235
HIGH 7.5
Red Hat Enterprise Linux 10 — A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenti…
2026-08-19
CVE-2026-76827
MEDIUM 6.8
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster t…
2026-08-19
CVE-2026-12564
CRITICAL 9.6
Red Hat Ansible Automation Platform 2 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in …
2026-08-18
CVE-2026-15571
HIGH 7.3
Red Hat Build Of Keycloak 26.6 — A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-sourc…
2026-08-18
CVE-2026-18963
CRITICAL 9.1
Red Hat Build Of Keycloak 26.4 — A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine fo…
2026-08-18
CVE-2026-19608
MEDIUM 5.3
Red Hat Build Of Keycloak — A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine…
2026-08-18
CVE-2026-66780
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assi…
2026-08-18
CVE-2026-66781
MEDIUM 6.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network…
2026-08-18
CVE-2026-66782
HIGH 7.8
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker…
2026-08-18
CVE-2026-66783
HIGH 8.2
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes.…
2026-08-18
CVE-2026-66793
HIGH 8.8
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management fo…
2026-08-18
CVE-2026-71365
HIGH 7.7
Red Hat Ansible Automation Platform 2 — A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When …
2026-08-18
CVE-2026-73834
MEDIUM 5.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain A…
2026-08-18
CVE-2026-75032
MEDIUM 6.3
Red Hat Enterprise Linux 10 — A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within …
2026-08-18
CVE-2026-75485
MEDIUM 5.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The clust…
2026-08-18
CVE-2026-75924
HIGH 8.7
Multicluster Engine For Kubernetes — A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting e…
2026-08-18
CVE-2026-15218
HIGH 7.9
Red Hat Openshift Ai (Rhoai) — A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These Servic…
2026-08-17
CVE-2026-66792
CRITICAL 9.9
Multicluster Global Hub — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a man…
2026-08-17
CVE-2026-66795
CRITICAL 9.1
Multicluster Engine For Kubernetes — A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval …
2026-08-17
CVE-2026-70495
HIGH 8.8
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions,…
2026-08-17
CVE-2026-71472
CRITICAL 9.1
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub ad…
2026-08-17
CVE-2026-13002
MEDIUM 4.4
Red Hat Enterprise Linux 10 — A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who…
2026-08-14
CVE-2026-19617
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata conf…
2026-08-14
CVE-2026-19879
MEDIUM 5.3
Red Hat Build Of Apache Camel For Spring Boot 4 — A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()…
2026-08-14
CVE-2026-58224
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validat…
2026-08-14
CVE-2026-74240
MEDIUM 5.4
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sig…
2026-08-14
CVE-2026-74241
MEDIUM 4.8
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handli…
2026-08-14
CVE-2026-74242
MEDIUM 5.3
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notifica…
2026-08-14
CVE-2026-74243
MEDIUM 6.5
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unaut…
2026-08-14
CVE-2026-74244
MEDIUM 5.9
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticate…
2026-08-14
CVE-2026-74245
MEDIUM 5.9
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID cou…
2026-08-14
CVE-2026-74247
MEDIUM 4.2
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can ex…
2026-08-14
CVE-2026-18728
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically d…
2026-08-13
CVE-2026-19730
MEDIUM 4.2
Red Hat Ansible Automation Platform 2 — The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but …● PoC
2026-08-13
CVE-2026-73266
HIGH 7.1
Multicluster Engine For Kubernetes — A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tena…
2026-08-13
CVE-2026-73583
MEDIUM 6.6
Red Hat Enterprise Linux 10 — A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserializati…
2026-08-13
CVE-2026-73584
MEDIUM 6.3
Red Hat Enterprise Linux 10 — A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privilege…
2026-08-13
CVE-2026-73585
MEDIUM 6.3
Red Hat Enterprise Linux 10 — A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts all…
2026-08-13
CVE-2026-13622
HIGH 8.8
Red Hat Container Native Virtualization 4.12 — A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration,…
2026-08-12
CVE-2026-18663
MEDIUM 5.9
Red Hat Directory Server 11 — A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array o…
2026-08-12
CVE-2026-18726
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment …
2026-08-12
CVE-2026-18727
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-…
2026-08-12
CVE-2026-19130
MEDIUM 5.8
Multicluster Engine For Kubernetes — A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker wit…
2026-08-12
CVE-2026-19548
MEDIUM 5.5
Red Hat Enterprise Linux 10 — Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the G…
2026-08-12
CVE-2026-19654
HIGH 7.5
Red Hat Enterprise Linux 10 — A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafte…
2026-08-12
CVE-2026-64927
MEDIUM 6.4
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific…
2026-08-12
CVE-2026-66878
HIGH 7.7
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrat…
2026-08-12
CVE-2026-70398
CRITICAL 9.6
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This …
2026-08-12
CVE-2026-71469
HIGH 7.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with uniqu…
2026-08-12
CVE-2026-71471
CRITICAL 9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specif…
2026-08-12
CVE-2026-71473
HIGH 8.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a m…
2026-08-12
CVE-2026-71846
MEDIUM 6.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster…
2026-08-12
CVE-2026-72508
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RH…
2026-08-12
CVE-2026-72526
CRITICAL 9.9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-integrations component. The Application propagation controller processes th…
2026-08-12
CVE-2026-73122
HIGH 7.7
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM).…
2026-08-12
CVE-2026-73268
CRITICAL 9.9
Multicluster Engine For Kubernetes — A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with creat…
2026-08-12
CVE-2026-73269
CRITICAL 9.9
Multicluster Engine For Kubernetes — A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resou…
2026-08-12
CVE-2026-73433
MEDIUM 6.6
Gst Plugins Good — A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk…
2026-08-12
CVE-2026-73434
MEDIUM 6.1
Gst Plugins Good — A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of a…
2026-08-12
CVE-2026-10579
CRITICAL 9.8
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions…
2026-08-11
CVE-2026-14180
MEDIUM 5.3
Red Hat Build Of Apache Camel For Spring Boot 4 — A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss …
2026-08-11
CVE-2026-15554
HIGH 7.4
Red Hat Jboss Enterprise Application Platform 7.4.25 — the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secre…
2026-08-11
CVE-2026-15555
HIGH 8.8
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session…
2026-08-11
CVE-2026-15556
HIGH 8.1
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements m…
2026-08-11
CVE-2026-15560
HIGH 8.1
Red Hat Jboss Enterprise Application Platform 7.4.25 — when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during obj…
2026-08-11
CVE-2026-15561
HIGH 7.5
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would a…
2026-08-11
CVE-2026-15562
HIGH 7.5
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or …
2026-08-11
CVE-2026-15563
HIGH 7.4
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication…
2026-08-11
CVE-2026-15565
HIGH 7.5
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authent…
2026-08-11
CVE-2026-15567
HIGH 7.5
Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS…
2026-08-11
CVE-2026-19078
MEDIUM 4.3
Red Hat Openshift Container Platform 4 — A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parame…
2026-08-11
CVE-2026-19391
MEDIUM 6.5
Pen Drive Powered By Red Hat Lightspeed — A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed …
2026-08-11
CVE-2026-19519
MEDIUM 4.3
Red Hat Advanced Cluster Security 4 — A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an…
2026-08-11
CVE-2026-19546
HIGH 8.8
Red Hat Enterprise Linux 10 — A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.
For a …
2026-08-11
CVE-2026-19550
HIGH 8.2
Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust o…
2026-08-11
CVE-2026-24329
MEDIUM 4.9
Red Hat Fuse 7 — A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed…
2026-08-11
CVE-2026-24330
MEDIUM 6.5
Red Hat Fuse 7 — A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and dep…
2026-08-11
CVE-2026-50236
HIGH 7.4
Red Hat Openshift Container Platform 4.18 — An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied targe…
2026-08-11
CVE-2026-50237
HIGH 7.4
Red Hat Openshift Container Platform 4.12 — A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A n…
2026-08-11
CVE-2026-71217
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channe…
2026-08-11
CVE-2026-71218
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()`…
2026-08-11
CVE-2026-71467
HIGH 7.5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally ski…
2026-08-11
CVE-2026-71468
MEDIUM 5.3
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it i…
2026-08-11
CVE-2026-71474
MEDIUM 6.3
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. When the application receives a non-200 response, it logs the request hea…
2026-08-11
CVE-2026-71475
MEDIUM 5
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unenc…
2026-08-11
CVE-2026-71845
MEDIUM 6.3
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it…
2026-08-11
CVE-2026-72693
HIGH 7.8
Red Hat Enterprise Linux 10 — `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a p…
2026-08-11
CVE-2026-72694
HIGH 7.1
Red Hat Enterprise Linux 10 — A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a …
2026-08-11
CVE-2026-13717
HIGH 8.8
Red Hat Openshift Ai 3.4 — A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a …
2026-08-10
CVE-2026-14450
CRITICAL 9.9
Red Hat Openshift Ai 3.4 — A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant …
2026-08-10
CVE-2026-15467
HIGH 8.1
Red Hat Openshift Ai 2.25 — A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the clu…
2026-08-10
CVE-2026-15581
HIGH 8
Red Hat Openshift Ai 2.25 — A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster ne…
2026-08-10
CVE-2026-16456
MEDIUM 6.5
Red Hat Openshift Ai 2.25 — A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resour…
2026-08-10
CVE-2026-18608
HIGH 8.7
Red Hat Openshift Ai 2.25 — A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its …
2026-08-10
CVE-2026-18611
HIGH 7.5
Red Hat Openshift Ai 2.25 — A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker…
2026-08-10
CVE-2026-18617
HIGH 8.8
Red Hat Openshift Ai 2.25 — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability…
2026-08-10
CVE-2026-18618
HIGH 7.5
Red Hat Openshift Ai 2.25 — A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulner…
2026-08-10
CVE-2026-18620
HIGH 7.1
Red Hat Openshift Ai 2.25 — A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorizatio…
2026-08-10
CVE-2026-18621
HIGH 7.6
Red Hat Openshift Ai 2.25 — A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass secu…
2026-08-10
CVE-2026-18941
HIGH 7.7
Red Hat Openshift Ai 2.25 — A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-o…
2026-08-10
CVE-2026-18942
MEDIUM 5.5
Red Hat Openshift Ai 2.25 — A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repo…
2026-08-10
CVE-2026-18947
HIGH 8.5
Red Hat Openshift Ai 2.25 — A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-i…
2026-08-10
CVE-2026-18948
CRITICAL 9.9
Red Hat Openshift Ai 2.25 — A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its regi…
2026-08-10
CVE-2026-18949
HIGH 8.8
Red Hat Openshift Ai 2.25 — A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's …
2026-08-10
CVE-2026-18950
HIGH 8.8
Red Hat Openshift Ai 2.25 — A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related …
2026-08-10
CVE-2026-18951
HIGH 8.8
Red Hat Openshift Ai 3.3 — A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay inco…
2026-08-10
CVE-2026-18982
HIGH 8.8
Red Hat Openshift Ai 2.25 — A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin …
2026-08-10
CVE-2026-19278
MEDIUM 6.8
Red Hat Advanced Cluster Security 4 — A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrat…
2026-08-10
CVE-2026-19387
HIGH 7.6
Red Hat Enterprise Linux 10 — A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when deco…
2026-08-10
CVE-2026-19389
HIGH 7.1
Red Hat Enterprise Linux 10 — Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demux…
2026-08-10
CVE-2026-19404
MEDIUM 6.5
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extend…
2026-08-10
CVE-2026-19411
LOW 3.9
Red Hat Enterprise Linux 7 — A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointe…
2026-08-10
CVE-2026-59087
HIGH 7.8
Red Hat Enterprise Linux 6 — A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader…● PoC
2026-08-10
CVE-2026-59088
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when process…
2026-08-10
CVE-2026-59090
HIGH 8.4
Red Hat Enterprise Linux 6 — A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `b…● PoC
2026-08-10
CVE-2026-59091
HIGH 7.3
Red Hat Enterprise Linux 6 — A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could…
2026-08-10
CVE-2026-63622
HIGH 7.8
Red Hat Enterprise Linux 10 — A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, co…
2026-08-10
CVE-2026-63623
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images we…
2026-08-10
CVE-2026-6426
MEDIUM 4.4
Red Hat Enterprise Linux 10 — A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination b…
2026-08-10
CVE-2026-71576
HIGH 8.5
Multicluster Global Hub — A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of…
2026-08-10
CVE-2026-71577
MEDIUM 6.3
Multicluster Global Hub — A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants a…
2026-08-10
CVE-2026-42170
HIGH 7.8
Red Hat Enterprise Linux 6 — A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a cra…
2026-08-08
CVE-2026-15816
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the…
2026-08-07
CVE-2026-18938
MEDIUM 6.2
Red Hat Enterprise Linux 10 — A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could…
2026-08-07
CVE-2026-19079
MEDIUM 4.4
Red Hat Hardened Images — A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policyco…
2026-08-07
CVE-2026-61477
LOW 2.3
Red Hat Enterprise Linux 10 — An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not stri…
2026-08-07
CVE-2026-18649
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader …
2026-08-06
CVE-2026-18967
MEDIUM 6.4
Red Hat Build Of Keycloak — A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When co…
2026-08-06
CVE-2026-7867
HIGH 7.8
Red Hat Enterprise Linux 10 — A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authoriz…
2026-08-06
CVE-2026-10059
CRITICAL 9.1
Multicluster Engine For Kubernetes — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator w…
2026-08-05
CVE-2026-10090
CRITICAL 9
Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat A…
2026-08-05
CVE-2026-15572
HIGH 8.8
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Prot…
2026-08-05
CVE-2026-15573
HIGH 8.1
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to…
2026-08-05
CVE-2026-16071
MEDIUM 5.4
Red Hat Build Of Keycloak 26.4 — A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from exte…
2026-08-05
CVE-2026-16100
MEDIUM 6.5
Red Hat Build Of Keycloak 26.6 — A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records…
2026-08-05
CVE-2026-16102
HIGH 8.1
Red Hat Build Of Keycloak 26.4 — A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access manage…
2026-08-05
CVE-2026-16442
HIGH 7.4
Red Hat Build Of Keycloak 26.4 — A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and use…
2026-08-05
CVE-2026-16443
HIGH 7.4
Red Hat Build Of Keycloak 26.4 — A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the co…
2026-08-05
CVE-2026-18839
LOW 2.2
Popt — An integer underflow was found in the popt library when formatting help text for option tables that exceed the…
2026-08-05
CVE-2026-44605
MEDIUM 5.5
Red Hat Hardened Images — A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vu…
2026-08-05
CVE-2026-49331
MEDIUM 6.5
Red Hat Openshift Container Platform 4 — A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the…
2026-08-05
CVE-2026-71225
MEDIUM 6.5
Libkcapi — A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 Ki…
2026-08-05
CVE-2026-71226
HIGH 7.3
Libkcapi — Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error befor…
2026-08-05
CVE-2026-71227
MEDIUM 5.1
Libkcapi — A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/O…
2026-08-05
CVE-2026-17614
MEDIUM 4.4
Red Hat Jboss Enterprise Application Platform 7 — A path traversal flaw was found in WildFly's domain mode
implementation. The LocalFileRepository.getFile() a…
2026-08-04
CVE-2026-18103
MEDIUM 4.9
Red Hat Enterprise Linux 6 — A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Applicati…
2026-08-04
CVE-2026-18569
LOW 3.7
Red Hat Build Of Keycloak — A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the R…
2026-08-04
CVE-2026-18739
LOW 2.5
Popt — A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs func…
2026-08-04
CVE-2026-42169
HIGH 7.3
Red Hat Enterprise Linux 9 — A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs w…
2026-08-04
CVE-2026-68743
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_to…
2026-08-04
CVE-2026-68744
LOW 3.3
Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply…
2026-08-04
CVE-2026-70367
MEDIUM 5.4
Stunnel — A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured i…● PoC
2026-08-04
CVE-2026-70368
MEDIUM 6.5
Stunnel — A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling overs…
2026-08-04
CVE-2026-18477
MEDIUM 4.4
Red Hat Hardened Images — A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows…
2026-08-03
CVE-2026-18508
MEDIUM 4.4
Red Hat Hardened Images — A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are …
2026-08-03
CVE-2026-18651
MEDIUM 5.4
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-lev…
2026-08-03
CVE-2026-68742
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate th…
2026-08-03
CVE-2026-6694
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animate…
2026-08-03
CVE-2026-6695
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially cra…
2026-08-03
CVE-2026-18570
MEDIUM 5.4
Red Hat Build Of Keycloak — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. Thi…
2026-08-02
CVE-2026-18571
MEDIUM 6.6
Red Hat Build Of Keycloak — A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) i…
2026-08-02
CVE-2026-18572
MEDIUM 6.5
Red Hat Build Of Keycloak — Keycloak provides authorization services that allow administrators to restrict access to resources based on ti…
2026-08-02
CVE-2026-18573
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and…
2026-08-02
CVE-2026-10079
HIGH 8.5
Red Hat Advanced Cluster Security 4 — A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deplo…
2026-07-31
CVE-2026-11770
HIGH 7.5
Red Hat Directory Server 11.7 E4s For Rhel 8 — A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters in…
2026-07-31
CVE-2026-15722
HIGH 7.5
Red Hat Directory Server 11.7 E4s For Rhel 8 — A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval()…
2026-07-31
CVE-2026-16105
MEDIUM 4.9
Red Hat Build Of Keycloak — A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-bas…
2026-07-31
CVE-2026-18141
HIGH 8.2
Red Hat Ansible Automation Platform 2.6 For Rhel 9 — A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An u…
2026-07-31
CVE-2026-18157
HIGH 7.8
Yggdrasil Worker Package Manager — A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system coul…
2026-07-31
CVE-2026-18203
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution.…
2026-07-31
CVE-2026-18206
LOW 3.7
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management…
2026-07-31
CVE-2026-18208
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an o…
2026-07-31
CVE-2026-18209
LOW 3.4
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentic…
2026-07-31
CVE-2026-18211
MEDIUM 4.2
Red Hat Build Of Keycloak — A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This componen…
2026-07-31
CVE-2026-18214
MEDIUM 6.8
Red Hat Build Of Keycloak — Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific …
2026-07-31
CVE-2026-18215
MEDIUM 6.8
Red Hat Build Of Keycloak — Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific or…
2026-07-31
CVE-2026-18217
LOW 3.4
Red Hat Build Of Keycloak — A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access managemen…
2026-07-31
CVE-2026-18218
MEDIUM 4.2
Red Hat Build Of Keycloak — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administra…
2026-07-31
CVE-2026-18358
HIGH 7.5
Gnome Remote Desktop — A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in…
2026-07-31
CVE-2026-16524
HIGH 7.8
Red Hat Enterprise Linux 10 — A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.per…
2026-07-30
CVE-2026-16526
HIGH 8.8
Red Hat Enterprise Linux 10 — A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code…
2026-07-30
CVE-2026-16527
HIGH 7.3
Red Hat Enterprise Linux 10 — An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /…
2026-07-30
CVE-2026-16529
HIGH 7.5
Red Hat Enterprise Linux 10 — A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during…
2026-07-30
CVE-2026-16530
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerab…
2026-07-30
CVE-2026-16531
MEDIUM 5.3
Red Hat Enterprise Linux 10 — An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servle…
2026-07-30
CVE-2026-18369
MEDIUM 5.8
Red Hat Certificate System 10 — A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address liter…
2026-07-30
CVE-2026-18378
HIGH 7.6
Cost Management Metrics Operator — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows u…
2026-07-30
CVE-2026-18381
HIGH 7.6
Cost Management Metrics Operator — A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfi…
2026-07-30
CVE-2026-18382
MEDIUM 6.8
Cost Management Metrics Operator — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a…
2026-07-30
CVE-2026-58216
MEDIUM 5.3
Red Hat Enterprise Linux 10 — An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpas…
2026-07-30
CVE-2026-58218
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to…
2026-07-30
CVE-2026-58222
HIGH 8.8
Red Hat Enterprise Linux 10 — A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Di…
2026-07-30
CVE-2026-68562
MEDIUM 6.2
Red Hat Enterprise Linux 10 — A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed nod…
2026-07-30
CVE-2026-68563
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privile…
2026-07-30
CVE-2026-18201
MEDIUM 5.5
Red Hat Build Of Keycloak — Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw …
2026-07-29
CVE-2026-18207
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system chec…
2026-07-29
CVE-2026-18220
HIGH 7.8
Red Hat Enterprise Linux 10 — An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU b…
2026-07-29
CVE-2026-18255
HIGH 7.2
Red Hat Quay 3 — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account token…
2026-07-29
CVE-2026-16313
HIGH 7.6
Red Hat Enterprise Linux 10 — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device ident…
2026-07-28
CVE-2026-17072
LOW 3.3
Red Hat Enterprise Linux 10 — A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when pa…
2026-07-28
CVE-2026-18047
MEDIUM 6.5
Red Hat Certificate System 10 — A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern m…
2026-07-28
CVE-2026-18107
HIGH 7.8
Red Hat Enterprise Linux 10 — A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious pro…
2026-07-28
CVE-2026-49332
HIGH 8.5
Red Hat Openshift Container Platform 4.12 — A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-varia…
2026-07-28
CVE-2026-12383
HIGH 7.5
Red Hat Ansible Automation Platform 2.5 For Rhel 8 — A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive acce…
2026-07-27
CVE-2026-15003
MEDIUM 5.6
Red Hat Hardened Images — A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow rea…
2026-07-27
CVE-2026-17523
HIGH 7.8
Red Hat Enterprise Linux 8 — A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploi…
2026-07-27
CVE-2026-17527
HIGH 7.7
Red Hat Openshift Virtualization 4 — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide rea…
2026-07-27
CVE-2026-66757
MEDIUM 5.5
Gimp — A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin alloc…● PoC
2026-07-27
CVE-2026-66758
HIGH 7.8
Gimp — A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates mem…
2026-07-27
CVE-2026-66759
HIGH 7.1
Gimp — A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processi…● PoC
2026-07-27
CVE-2026-16730
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors durin…
2026-07-24
CVE-2026-16743
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filenam…● PoC
2026-07-24
CVE-2026-16910
MEDIUM 5.5
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification ha…
2026-07-24
CVE-2026-17039
LOW 3.1
Red Hat Certificate System 10 — A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-b…
2026-07-24
CVE-2026-17048
MEDIUM 5.5
Red Hat Build Of Keycloak 26.6 — A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issu…
2026-07-24
CVE-2026-17059
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of t…
2026-07-24
CVE-2026-17107
HIGH 8.5
Multicluster Engine For Kubernetes 2.1 — A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for …
2026-07-24
CVE-2026-66337
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() functi…
2026-07-24
CVE-2026-66338
MEDIUM 5.4
Red Hat Enterprise Linux 10 — A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk…
2026-07-24
CVE-2026-66339
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly …
2026-07-24
CVE-2026-12353
MEDIUM 5.3
Red Hat Certificate System 9 — An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by rep…
2026-07-23
CVE-2026-16745
HIGH 8.8
Red Hat Openshift Ai 2.25 — A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect…
2026-07-23
CVE-2026-16768
MEDIUM 5.3
Gdk Pixbuf — A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the de…● PoC
2026-07-23
CVE-2026-64611
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when p…
2026-07-23
CVE-2026-6390
MEDIUM 6.8
Red Hat Enterprise Linux 10 — A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startu…
2026-07-23
CVE-2026-16473
MEDIUM 4.3
Red Hat Enterprise Linux 10 — A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a c…
2026-07-22
CVE-2026-16544
MEDIUM 6.5
Red Hat Ansible Automation Platform 2 — A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups…
2026-07-22
CVE-2026-16560
MEDIUM 5.3
Red Hat Directory Server 11 — A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted va…
2026-07-22
CVE-2026-16615
MEDIUM 6.8
Librest — A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the …
2026-07-22
CVE-2026-44187
LOW 3.3
Red Hat Ansible Automation Platform 2 — A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an atta…
2026-07-22
CVE-2026-44189
HIGH 7.8
Red Hat Ansible Automation Platform 2 — A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This com…
2026-07-22
CVE-2026-44190
HIGH 7.8
Red Hat Ansible Automation Platform 2 — A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability …
2026-07-22
CVE-2026-44191
HIGH 7.8
Red Hat Ansible Automation Platform 2 — A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability …
2026-07-22
CVE-2026-44192
MEDIUM 6.6
Red Hat Ansible Automation Platform 2 — A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as p…
2026-07-22
CVE-2026-12547
LOW 3.4
Red Hat Enterprise Linux 10 — SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port…
2026-07-21
CVE-2026-12548
MEDIUM 4.2
Red Hat Enterprise Linux 10 — A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mis…● PoC
2026-07-21
CVE-2026-15370
MEDIUM 6.7
Red Hat Enterprise Linux 10 — A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsaf…
2026-07-21
CVE-2026-15811
MEDIUM 5.8
Red Hat Enterprise Linux 10 — A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framewor…
2026-07-21
CVE-2026-15812
MEDIUM 4.8
Red Hat Enterprise Linux 10 — A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: …
2026-07-21
CVE-2026-15927
MEDIUM 6.8
Red Hat Quay 3.1 — A flaw was found in Red Hat Quay's repository-level mirror configuration
feature. The POST and PUT handlers in…
2026-07-21
CVE-2026-16445
HIGH 7.5
Red Hat Enterprise Linux 8 — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by provid…
2026-07-21
CVE-2026-16461
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcin…
2026-07-21
CVE-2026-16493
HIGH 7.8
Red Hat Ansible Automation Platform 2 — A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artif…
2026-07-21
CVE-2026-16517
LOW 2.9
Red Hat Hardened Images — A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header …
2026-07-21
CVE-2026-59842
LOW 3.7
Red Hat Enterprise Linux 10 — A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key sh…
2026-07-21
CVE-2026-59843
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CH…
2026-07-21
CVE-2026-59844
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily …
2026-07-21
CVE-2026-59845
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID…
2026-07-21
CVE-2026-59846
LOW 3.9
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell…
2026-07-21
CVE-2026-59847
MEDIUM 5.9
Red Hat Enterprise Linux 10 — A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effe…
2026-07-21
CVE-2026-59848
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh cli…
2026-07-21
CVE-2026-59849
LOW 3.1
Red Hat Enterprise Linux 10 — A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause li…
2026-07-21
CVE-2026-59850
MEDIUM 4.3
Red Hat Enterprise Linux 10 — A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks ca…
2026-07-21
CVE-2026-59851
HIGH 8.8
Red Hat Enterprise Linux 10 — A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify w…
2026-07-21
CVE-2026-12080
HIGH 7.3
Red Hat Enterprise Linux 10 — A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the g…
2026-07-20
CVE-2026-12701
CRITICAL 9
Red Hat Ansible Automation Platform 2.5 For Rhel 8 — A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that …
2026-07-20
CVE-2026-15588
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gd…● PoC
2026-07-20
CVE-2026-15813
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34…
2026-07-20
CVE-2026-16242
CRITICAL 9.4
Multicluster Engine For Kubernetes 2.1 — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing li…
2026-07-20
CVE-2026-16254
MEDIUM 4.3
Red Hat Advanced Cluster Security 4 — A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can …
2026-07-20
CVE-2026-16277
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service w…
2026-07-20
CVE-2026-64612
HIGH 7.5
Red Hat Enterprise Linux 10 — A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader wi…
2026-07-20
CVE-2026-15943
MEDIUM 5.5
Red Hat Build Of Keycloak — A flaw was found in the Keycloak keycloak-services component, which handles the management of identity provide…
2026-07-17
CVE-2026-16072
MEDIUM 4.9
Red Hat Build Of Keycloak — A flaw was found in the organization management component of Keycloak. A delegated administrator with permissi…
2026-07-17
CVE-2026-16089
MEDIUM 5.4
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAu…
2026-07-17
CVE-2026-16093
MEDIUM 5.4
Red Hat Build Of Keycloak — Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requ…
2026-07-17
CVE-2026-16103
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-…
2026-07-17
CVE-2026-16104
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the…
2026-07-17
CVE-2026-16106
MEDIUM 4.9
Red Hat Build Of Keycloak — A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue o…
2026-07-17
CVE-2026-16108
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is r…
2026-07-17
CVE-2026-16118
HIGH 7.1
Xdgmime — A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line…● PoC
2026-07-17
CVE-2026-15945
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grai…
2026-07-16
CVE-2026-1609
HIGH 8.1
Keycloak — A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and…
2026-07-16
CVE-2026-23538
HIGH 7.5
Feast Feature Server — A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers …
2026-07-16