← Browse

Red Hat

300 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-73267 HIGH 7.7 Multicluster Engine For Kubernetes — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standar… 2026-08-21 CVE-2026-11861 CRITICAL 9.6 Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Act… 2026-08-20 CVE-2026-13097 CRITICAL 9.1 Red Hat Enterprise Linux 10 — A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal nam… 2026-08-20 CVE-2026-18917 HIGH 7.8 Red Hat Enterprise Linux 10 — A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the… 2026-08-20 CVE-2026-19582 HIGH 7.8 Migration Toolkit For Containers — In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbit… 2026-08-20 CVE-2026-19611 HIGH 7.4 Red Hat Build Of Apache Camel 4 For Quarkus 3 — A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, whic… 2026-08-20 CVE-2026-66785 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traf… 2026-08-20 CVE-2026-66787 HIGH 8.7 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulne… 2026-08-20 CVE-2026-66788 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerabilit… 2026-08-20 CVE-2026-67567 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who h… 2026-08-20 CVE-2026-73137 HIGH 7.7 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RH… 2026-08-20 CVE-2026-73196 MEDIUM 4.3 Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting a… 2026-08-20 CVE-2026-73197 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending over… 2026-08-20 CVE-2026-73198 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_… 2026-08-20 CVE-2026-73199 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointe…● PoC 2026-08-20 CVE-2026-77014 MEDIUM 5.3 Red Hat Enterprise Linux 10 — A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-me… 2026-08-20 CVE-2026-77176 HIGH 8.1 Red Hat Openshift Container Platform 4 — A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest p… 2026-08-20 CVE-2026-18874 MEDIUM 6.2 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (… 2026-08-19 CVE-2026-43961 HIGH 7.8 Vim — A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragment… 2026-08-19 CVE-2026-66794 CRITICAL 9.3 Multicluster Engine For Kubernetes — A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerabil… 2026-08-19 CVE-2026-70496 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster adm… 2026-08-19 CVE-2026-71470 CRITICAL 9.1 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom… 2026-08-19 CVE-2026-75569 HIGH 7.7 Multicluster Engine For Kubernetes — A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote reposito… 2026-08-19 CVE-2026-75900 MEDIUM 6.1 Red Hat Enterprise Linux 10 — An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard c… 2026-08-19 CVE-2026-76139 HIGH 8 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from… 2026-08-19 CVE-2026-76166 MEDIUM 4.3 Red Hat Jboss Enterprise Application Platform 7 — A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted U… 2026-08-19 CVE-2026-76235 HIGH 7.5 Red Hat Enterprise Linux 10 — A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenti… 2026-08-19 CVE-2026-76827 MEDIUM 6.8 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster t… 2026-08-19 CVE-2026-12564 CRITICAL 9.6 Red Hat Ansible Automation Platform 2 — A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in … 2026-08-18 CVE-2026-15571 HIGH 7.3 Red Hat Build Of Keycloak 26.6 — A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-sourc… 2026-08-18 CVE-2026-18963 CRITICAL 9.1 Red Hat Build Of Keycloak 26.4 — A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine fo… 2026-08-18 CVE-2026-19608 MEDIUM 5.3 Red Hat Build Of Keycloak — A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine… 2026-08-18 CVE-2026-66780 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assi… 2026-08-18 CVE-2026-66781 MEDIUM 6.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network… 2026-08-18 CVE-2026-66782 HIGH 7.8 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker… 2026-08-18 CVE-2026-66783 HIGH 8.2 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes.… 2026-08-18 CVE-2026-66793 HIGH 8.8 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management fo… 2026-08-18 CVE-2026-71365 HIGH 7.7 Red Hat Ansible Automation Platform 2 — A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When … 2026-08-18 CVE-2026-73834 MEDIUM 5.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain A… 2026-08-18 CVE-2026-75032 MEDIUM 6.3 Red Hat Enterprise Linux 10 — A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within … 2026-08-18 CVE-2026-75485 MEDIUM 5.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The clust… 2026-08-18 CVE-2026-75924 HIGH 8.7 Multicluster Engine For Kubernetes — A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting e… 2026-08-18 CVE-2026-15218 HIGH 7.9 Red Hat Openshift Ai (Rhoai) — A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These Servic… 2026-08-17 CVE-2026-66792 CRITICAL 9.9 Multicluster Global Hub — A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a man… 2026-08-17 CVE-2026-66795 CRITICAL 9.1 Multicluster Engine For Kubernetes — A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval … 2026-08-17 CVE-2026-70495 HIGH 8.8 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions,… 2026-08-17 CVE-2026-71472 CRITICAL 9.1 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub ad… 2026-08-17 CVE-2026-13002 MEDIUM 4.4 Red Hat Enterprise Linux 10 — A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who… 2026-08-14 CVE-2026-19617 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata conf… 2026-08-14 CVE-2026-19879 MEDIUM 5.3 Red Hat Build Of Apache Camel For Spring Boot 4 — A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()… 2026-08-14 CVE-2026-58224 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validat… 2026-08-14 CVE-2026-74240 MEDIUM 5.4 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sig… 2026-08-14 CVE-2026-74241 MEDIUM 4.8 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handli… 2026-08-14 CVE-2026-74242 MEDIUM 5.3 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notifica… 2026-08-14 CVE-2026-74243 MEDIUM 6.5 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unaut… 2026-08-14 CVE-2026-74244 MEDIUM 5.9 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticate… 2026-08-14 CVE-2026-74245 MEDIUM 5.9 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID cou… 2026-08-14 CVE-2026-74247 MEDIUM 4.2 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can ex… 2026-08-14 CVE-2026-18728 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically d… 2026-08-13 CVE-2026-19730 MEDIUM 4.2 Red Hat Ansible Automation Platform 2 — The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but …● PoC 2026-08-13 CVE-2026-73266 HIGH 7.1 Multicluster Engine For Kubernetes — A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tena… 2026-08-13 CVE-2026-73583 MEDIUM 6.6 Red Hat Enterprise Linux 10 — A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserializati… 2026-08-13 CVE-2026-73584 MEDIUM 6.3 Red Hat Enterprise Linux 10 — A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privilege… 2026-08-13 CVE-2026-73585 MEDIUM 6.3 Red Hat Enterprise Linux 10 — A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts all… 2026-08-13 CVE-2026-13622 HIGH 8.8 Red Hat Container Native Virtualization 4.12 — A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration,… 2026-08-12 CVE-2026-18663 MEDIUM 5.9 Red Hat Directory Server 11 — A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array o… 2026-08-12 CVE-2026-18726 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment … 2026-08-12 CVE-2026-18727 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-… 2026-08-12 CVE-2026-19130 MEDIUM 5.8 Multicluster Engine For Kubernetes — A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker wit… 2026-08-12 CVE-2026-19548 MEDIUM 5.5 Red Hat Enterprise Linux 10 — Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the G… 2026-08-12 CVE-2026-19654 HIGH 7.5 Red Hat Enterprise Linux 10 — A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafte… 2026-08-12 CVE-2026-64927 MEDIUM 6.4 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific… 2026-08-12 CVE-2026-66878 HIGH 7.7 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrat… 2026-08-12 CVE-2026-70398 CRITICAL 9.6 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This … 2026-08-12 CVE-2026-71469 HIGH 7.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with uniqu… 2026-08-12 CVE-2026-71471 CRITICAL 9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specif… 2026-08-12 CVE-2026-71473 HIGH 8.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a m… 2026-08-12 CVE-2026-71846 MEDIUM 6.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster… 2026-08-12 CVE-2026-72508 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RH… 2026-08-12 CVE-2026-72526 CRITICAL 9.9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-integrations component. The Application propagation controller processes th… 2026-08-12 CVE-2026-73122 HIGH 7.7 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM).… 2026-08-12 CVE-2026-73268 CRITICAL 9.9 Multicluster Engine For Kubernetes — A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with creat… 2026-08-12 CVE-2026-73269 CRITICAL 9.9 Multicluster Engine For Kubernetes — A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resou… 2026-08-12 CVE-2026-73433 MEDIUM 6.6 Gst Plugins Good — A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk… 2026-08-12 CVE-2026-73434 MEDIUM 6.1 Gst Plugins Good — A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of a… 2026-08-12 CVE-2026-10579 CRITICAL 9.8 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions… 2026-08-11 CVE-2026-14180 MEDIUM 5.3 Red Hat Build Of Apache Camel For Spring Boot 4 — A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss … 2026-08-11 CVE-2026-15554 HIGH 7.4 Red Hat Jboss Enterprise Application Platform 7.4.25 — the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secre… 2026-08-11 CVE-2026-15555 HIGH 8.8 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session… 2026-08-11 CVE-2026-15556 HIGH 8.1 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements m… 2026-08-11 CVE-2026-15560 HIGH 8.1 Red Hat Jboss Enterprise Application Platform 7.4.25 — when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during obj… 2026-08-11 CVE-2026-15561 HIGH 7.5 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would a… 2026-08-11 CVE-2026-15562 HIGH 7.5 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or … 2026-08-11 CVE-2026-15563 HIGH 7.4 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication… 2026-08-11 CVE-2026-15565 HIGH 7.5 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authent… 2026-08-11 CVE-2026-15567 HIGH 7.5 Red Hat Jboss Enterprise Application Platform 7.4.25 — A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS… 2026-08-11 CVE-2026-19078 MEDIUM 4.3 Red Hat Openshift Container Platform 4 — A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parame… 2026-08-11 CVE-2026-19391 MEDIUM 6.5 Pen Drive Powered By Red Hat Lightspeed — A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed … 2026-08-11 CVE-2026-19519 MEDIUM 4.3 Red Hat Advanced Cluster Security 4 — A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an… 2026-08-11 CVE-2026-19546 HIGH 8.8 Red Hat Enterprise Linux 10 — A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a … 2026-08-11 CVE-2026-19550 HIGH 8.2 Red Hat Enterprise Linux 10 — A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust o… 2026-08-11 CVE-2026-24329 MEDIUM 4.9 Red Hat Fuse 7 — A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed… 2026-08-11 CVE-2026-24330 MEDIUM 6.5 Red Hat Fuse 7 — A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and dep… 2026-08-11 CVE-2026-50236 HIGH 7.4 Red Hat Openshift Container Platform 4.18 — An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied targe… 2026-08-11 CVE-2026-50237 HIGH 7.4 Red Hat Openshift Container Platform 4.12 — A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A n… 2026-08-11 CVE-2026-71217 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channe… 2026-08-11 CVE-2026-71218 MEDIUM 5.3 Red Hat Enterprise Linux 10 — A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()`… 2026-08-11 CVE-2026-71467 HIGH 7.5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally ski… 2026-08-11 CVE-2026-71468 MEDIUM 5.3 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it i… 2026-08-11 CVE-2026-71474 MEDIUM 6.3 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. When the application receives a non-200 response, it logs the request hea… 2026-08-11 CVE-2026-71475 MEDIUM 5 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unenc… 2026-08-11 CVE-2026-71845 MEDIUM 6.3 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it… 2026-08-11 CVE-2026-72693 HIGH 7.8 Red Hat Enterprise Linux 10 — `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a p… 2026-08-11 CVE-2026-72694 HIGH 7.1 Red Hat Enterprise Linux 10 — A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a … 2026-08-11 CVE-2026-13717 HIGH 8.8 Red Hat Openshift Ai 3.4 — A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a … 2026-08-10 CVE-2026-14450 CRITICAL 9.9 Red Hat Openshift Ai 3.4 — A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant … 2026-08-10 CVE-2026-15467 HIGH 8.1 Red Hat Openshift Ai 2.25 — A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the clu… 2026-08-10 CVE-2026-15581 HIGH 8 Red Hat Openshift Ai 2.25 — A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster ne… 2026-08-10 CVE-2026-16456 MEDIUM 6.5 Red Hat Openshift Ai 2.25 — A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resour… 2026-08-10 CVE-2026-18608 HIGH 8.7 Red Hat Openshift Ai 2.25 — A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its … 2026-08-10 CVE-2026-18611 HIGH 7.5 Red Hat Openshift Ai 2.25 — A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker… 2026-08-10 CVE-2026-18617 HIGH 8.8 Red Hat Openshift Ai 2.25 — A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability… 2026-08-10 CVE-2026-18618 HIGH 7.5 Red Hat Openshift Ai 2.25 — A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulner… 2026-08-10 CVE-2026-18620 HIGH 7.1 Red Hat Openshift Ai 2.25 — A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorizatio… 2026-08-10 CVE-2026-18621 HIGH 7.6 Red Hat Openshift Ai 2.25 — A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass secu… 2026-08-10 CVE-2026-18941 HIGH 7.7 Red Hat Openshift Ai 2.25 — A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-o… 2026-08-10 CVE-2026-18942 MEDIUM 5.5 Red Hat Openshift Ai 2.25 — A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repo… 2026-08-10 CVE-2026-18947 HIGH 8.5 Red Hat Openshift Ai 2.25 — A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-i… 2026-08-10 CVE-2026-18948 CRITICAL 9.9 Red Hat Openshift Ai 2.25 — A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its regi… 2026-08-10 CVE-2026-18949 HIGH 8.8 Red Hat Openshift Ai 2.25 — A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's … 2026-08-10 CVE-2026-18950 HIGH 8.8 Red Hat Openshift Ai 2.25 — A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related … 2026-08-10 CVE-2026-18951 HIGH 8.8 Red Hat Openshift Ai 3.3 — A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay inco… 2026-08-10 CVE-2026-18982 HIGH 8.8 Red Hat Openshift Ai 2.25 — A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin … 2026-08-10 CVE-2026-19278 MEDIUM 6.8 Red Hat Advanced Cluster Security 4 — A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrat… 2026-08-10 CVE-2026-19387 HIGH 7.6 Red Hat Enterprise Linux 10 — A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when deco… 2026-08-10 CVE-2026-19389 HIGH 7.1 Red Hat Enterprise Linux 10 — Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demux… 2026-08-10 CVE-2026-19404 MEDIUM 6.5 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extend… 2026-08-10 CVE-2026-19411 LOW 3.9 Red Hat Enterprise Linux 7 — A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointe… 2026-08-10 CVE-2026-59087 HIGH 7.8 Red Hat Enterprise Linux 6 — A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader…● PoC 2026-08-10 CVE-2026-59088 MEDIUM 5.5 Red Hat Enterprise Linux 6 — A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when process… 2026-08-10 CVE-2026-59090 HIGH 8.4 Red Hat Enterprise Linux 6 — A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `b…● PoC 2026-08-10 CVE-2026-59091 HIGH 7.3 Red Hat Enterprise Linux 6 — A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could… 2026-08-10 CVE-2026-63622 HIGH 7.8 Red Hat Enterprise Linux 10 — A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, co… 2026-08-10 CVE-2026-63623 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images we… 2026-08-10 CVE-2026-6426 MEDIUM 4.4 Red Hat Enterprise Linux 10 — A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination b… 2026-08-10 CVE-2026-71576 HIGH 8.5 Multicluster Global Hub — A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of… 2026-08-10 CVE-2026-71577 MEDIUM 6.3 Multicluster Global Hub — A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants a… 2026-08-10 CVE-2026-42170 HIGH 7.8 Red Hat Enterprise Linux 6 — A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a cra… 2026-08-08 CVE-2026-15816 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the… 2026-08-07 CVE-2026-18938 MEDIUM 6.2 Red Hat Enterprise Linux 10 — A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could… 2026-08-07 CVE-2026-19079 MEDIUM 4.4 Red Hat Hardened Images — A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policyco… 2026-08-07 CVE-2026-61477 LOW 2.3 Red Hat Enterprise Linux 10 — An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not stri… 2026-08-07 CVE-2026-18649 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader … 2026-08-06 CVE-2026-18967 MEDIUM 6.4 Red Hat Build Of Keycloak — A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When co… 2026-08-06 CVE-2026-7867 HIGH 7.8 Red Hat Enterprise Linux 10 — A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authoriz… 2026-08-06 CVE-2026-10059 CRITICAL 9.1 Multicluster Engine For Kubernetes — A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator w… 2026-08-05 CVE-2026-10090 CRITICAL 9 Red Hat Advanced Cluster Management For Kubernetes 2 — A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat A… 2026-08-05 CVE-2026-15572 HIGH 8.8 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Prot… 2026-08-05 CVE-2026-15573 HIGH 8.1 Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to… 2026-08-05 CVE-2026-16071 MEDIUM 5.4 Red Hat Build Of Keycloak 26.4 — A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from exte… 2026-08-05 CVE-2026-16100 MEDIUM 6.5 Red Hat Build Of Keycloak 26.6 — A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records… 2026-08-05 CVE-2026-16102 HIGH 8.1 Red Hat Build Of Keycloak 26.4 — A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access manage… 2026-08-05 CVE-2026-16442 HIGH 7.4 Red Hat Build Of Keycloak 26.4 — A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and use… 2026-08-05 CVE-2026-16443 HIGH 7.4 Red Hat Build Of Keycloak 26.4 — A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the co… 2026-08-05 CVE-2026-18839 LOW 2.2 Popt — An integer underflow was found in the popt library when formatting help text for option tables that exceed the… 2026-08-05 CVE-2026-44605 MEDIUM 5.5 Red Hat Hardened Images — A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vu… 2026-08-05 CVE-2026-49331 MEDIUM 6.5 Red Hat Openshift Container Platform 4 — A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the… 2026-08-05 CVE-2026-71225 MEDIUM 6.5 Libkcapi — A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 Ki… 2026-08-05 CVE-2026-71226 HIGH 7.3 Libkcapi — Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error befor… 2026-08-05 CVE-2026-71227 MEDIUM 5.1 Libkcapi — A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/O… 2026-08-05 CVE-2026-17614 MEDIUM 4.4 Red Hat Jboss Enterprise Application Platform 7 — A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() a… 2026-08-04 CVE-2026-18103 MEDIUM 4.9 Red Hat Enterprise Linux 6 — A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Applicati… 2026-08-04 CVE-2026-18569 LOW 3.7 Red Hat Build Of Keycloak — A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the R… 2026-08-04 CVE-2026-18739 LOW 2.5 Popt — A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs func… 2026-08-04 CVE-2026-42169 HIGH 7.3 Red Hat Enterprise Linux 9 — A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs w… 2026-08-04 CVE-2026-68743 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_to… 2026-08-04 CVE-2026-68744 LOW 3.3 Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply… 2026-08-04 CVE-2026-70367 MEDIUM 5.4 Stunnel — A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured i…● PoC 2026-08-04 CVE-2026-70368 MEDIUM 6.5 Stunnel — A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling overs… 2026-08-04 CVE-2026-18477 MEDIUM 4.4 Red Hat Hardened Images — A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows… 2026-08-03 CVE-2026-18508 MEDIUM 4.4 Red Hat Hardened Images — A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are … 2026-08-03 CVE-2026-18651 MEDIUM 5.4 Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-lev… 2026-08-03 CVE-2026-68742 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate th… 2026-08-03 CVE-2026-6694 MEDIUM 5.5 Red Hat Enterprise Linux 6 — A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animate… 2026-08-03 CVE-2026-6695 MEDIUM 5.5 Red Hat Enterprise Linux 6 — A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially cra… 2026-08-03 CVE-2026-18570 MEDIUM 5.4 Red Hat Build Of Keycloak — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. Thi… 2026-08-02 CVE-2026-18571 MEDIUM 6.6 Red Hat Build Of Keycloak — A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) i… 2026-08-02 CVE-2026-18572 MEDIUM 6.5 Red Hat Build Of Keycloak — Keycloak provides authorization services that allow administrators to restrict access to resources based on ti… 2026-08-02 CVE-2026-18573 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and… 2026-08-02 CVE-2026-10079 HIGH 8.5 Red Hat Advanced Cluster Security 4 — A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deplo… 2026-07-31 CVE-2026-11770 HIGH 7.5 Red Hat Directory Server 11.7 E4s For Rhel 8 — A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters in… 2026-07-31 CVE-2026-15722 HIGH 7.5 Red Hat Directory Server 11.7 E4s For Rhel 8 — A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval()… 2026-07-31 CVE-2026-16105 MEDIUM 4.9 Red Hat Build Of Keycloak — A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-bas… 2026-07-31 CVE-2026-18141 HIGH 8.2 Red Hat Ansible Automation Platform 2.6 For Rhel 9 — A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An u… 2026-07-31 CVE-2026-18157 HIGH 7.8 Yggdrasil Worker Package Manager — A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system coul… 2026-07-31 CVE-2026-18203 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution.… 2026-07-31 CVE-2026-18206 LOW 3.7 Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management… 2026-07-31 CVE-2026-18208 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an o… 2026-07-31 CVE-2026-18209 LOW 3.4 Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentic… 2026-07-31 CVE-2026-18211 MEDIUM 4.2 Red Hat Build Of Keycloak — A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This componen… 2026-07-31 CVE-2026-18214 MEDIUM 6.8 Red Hat Build Of Keycloak — Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific … 2026-07-31 CVE-2026-18215 MEDIUM 6.8 Red Hat Build Of Keycloak — Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific or… 2026-07-31 CVE-2026-18217 LOW 3.4 Red Hat Build Of Keycloak — A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access managemen… 2026-07-31 CVE-2026-18218 MEDIUM 4.2 Red Hat Build Of Keycloak — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administra… 2026-07-31 CVE-2026-18358 HIGH 7.5 Gnome Remote Desktop — A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in… 2026-07-31 CVE-2026-16524 HIGH 7.8 Red Hat Enterprise Linux 10 — A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.per… 2026-07-30 CVE-2026-16526 HIGH 8.8 Red Hat Enterprise Linux 10 — A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code… 2026-07-30 CVE-2026-16527 HIGH 7.3 Red Hat Enterprise Linux 10 — An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /… 2026-07-30 CVE-2026-16529 HIGH 7.5 Red Hat Enterprise Linux 10 — A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during… 2026-07-30 CVE-2026-16530 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerab… 2026-07-30 CVE-2026-16531 MEDIUM 5.3 Red Hat Enterprise Linux 10 — An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servle… 2026-07-30 CVE-2026-18369 MEDIUM 5.8 Red Hat Certificate System 10 — A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address liter… 2026-07-30 CVE-2026-18378 HIGH 7.6 Cost Management Metrics Operator — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows u… 2026-07-30 CVE-2026-18381 HIGH 7.6 Cost Management Metrics Operator — A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfi… 2026-07-30 CVE-2026-18382 MEDIUM 6.8 Cost Management Metrics Operator — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a… 2026-07-30 CVE-2026-58216 MEDIUM 5.3 Red Hat Enterprise Linux 10 — An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpas… 2026-07-30 CVE-2026-58218 MEDIUM 5.3 Red Hat Enterprise Linux 10 — A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to… 2026-07-30 CVE-2026-58222 HIGH 8.8 Red Hat Enterprise Linux 10 — A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Di… 2026-07-30 CVE-2026-68562 MEDIUM 6.2 Red Hat Enterprise Linux 10 — A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed nod… 2026-07-30 CVE-2026-68563 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privile… 2026-07-30 CVE-2026-18201 MEDIUM 5.5 Red Hat Build Of Keycloak — Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw … 2026-07-29 CVE-2026-18207 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system chec… 2026-07-29 CVE-2026-18220 HIGH 7.8 Red Hat Enterprise Linux 10 — An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU b… 2026-07-29 CVE-2026-18255 HIGH 7.2 Red Hat Quay 3 — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account token… 2026-07-29 CVE-2026-16313 HIGH 7.6 Red Hat Enterprise Linux 10 — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device ident… 2026-07-28 CVE-2026-17072 LOW 3.3 Red Hat Enterprise Linux 10 — A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when pa… 2026-07-28 CVE-2026-18047 MEDIUM 6.5 Red Hat Certificate System 10 — A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern m… 2026-07-28 CVE-2026-18107 HIGH 7.8 Red Hat Enterprise Linux 10 — A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious pro… 2026-07-28 CVE-2026-49332 HIGH 8.5 Red Hat Openshift Container Platform 4.12 — A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-varia… 2026-07-28 CVE-2026-12383 HIGH 7.5 Red Hat Ansible Automation Platform 2.5 For Rhel 8 — A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive acce… 2026-07-27 CVE-2026-15003 MEDIUM 5.6 Red Hat Hardened Images — A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow rea… 2026-07-27 CVE-2026-17523 HIGH 7.8 Red Hat Enterprise Linux 8 — A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploi… 2026-07-27 CVE-2026-17527 HIGH 7.7 Red Hat Openshift Virtualization 4 — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide rea… 2026-07-27 CVE-2026-66757 MEDIUM 5.5 Gimp — A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin alloc…● PoC 2026-07-27 CVE-2026-66758 HIGH 7.8 Gimp — A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates mem… 2026-07-27 CVE-2026-66759 HIGH 7.1 Gimp — A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processi…● PoC 2026-07-27 CVE-2026-16730 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors durin… 2026-07-24 CVE-2026-16743 MEDIUM 5.5 Red Hat Enterprise Linux 10 — A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filenam…● PoC 2026-07-24 CVE-2026-16910 MEDIUM 5.5 Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification ha… 2026-07-24 CVE-2026-17039 LOW 3.1 Red Hat Certificate System 10 — A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-b… 2026-07-24 CVE-2026-17048 MEDIUM 5.5 Red Hat Build Of Keycloak 26.6 — A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issu… 2026-07-24 CVE-2026-17059 MEDIUM 6.5 Red Hat Build Of Keycloak — A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of t… 2026-07-24 CVE-2026-17107 HIGH 8.5 Multicluster Engine For Kubernetes 2.1 — A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for … 2026-07-24 CVE-2026-66337 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() functi… 2026-07-24 CVE-2026-66338 MEDIUM 5.4 Red Hat Enterprise Linux 10 — A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk… 2026-07-24 CVE-2026-66339 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly … 2026-07-24 CVE-2026-12353 MEDIUM 5.3 Red Hat Certificate System 9 — An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by rep… 2026-07-23 CVE-2026-16745 HIGH 8.8 Red Hat Openshift Ai 2.25 — A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect… 2026-07-23 CVE-2026-16768 MEDIUM 5.3 Gdk Pixbuf — A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the de…● PoC 2026-07-23 CVE-2026-64611 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when p… 2026-07-23 CVE-2026-6390 MEDIUM 6.8 Red Hat Enterprise Linux 10 — A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startu… 2026-07-23 CVE-2026-16473 MEDIUM 4.3 Red Hat Enterprise Linux 10 — A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a c… 2026-07-22 CVE-2026-16544 MEDIUM 6.5 Red Hat Ansible Automation Platform 2 — A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups… 2026-07-22 CVE-2026-16560 MEDIUM 5.3 Red Hat Directory Server 11 — A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted va… 2026-07-22 CVE-2026-16615 MEDIUM 6.8 Librest — A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the … 2026-07-22 CVE-2026-44187 LOW 3.3 Red Hat Ansible Automation Platform 2 — A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an atta… 2026-07-22 CVE-2026-44189 HIGH 7.8 Red Hat Ansible Automation Platform 2 — A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This com… 2026-07-22 CVE-2026-44190 HIGH 7.8 Red Hat Ansible Automation Platform 2 — A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability … 2026-07-22 CVE-2026-44191 HIGH 7.8 Red Hat Ansible Automation Platform 2 — A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability … 2026-07-22 CVE-2026-44192 MEDIUM 6.6 Red Hat Ansible Automation Platform 2 — A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as p… 2026-07-22 CVE-2026-12547 LOW 3.4 Red Hat Enterprise Linux 10 — SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port… 2026-07-21 CVE-2026-12548 MEDIUM 4.2 Red Hat Enterprise Linux 10 — A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mis…● PoC 2026-07-21 CVE-2026-15370 MEDIUM 6.7 Red Hat Enterprise Linux 10 — A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsaf… 2026-07-21 CVE-2026-15811 MEDIUM 5.8 Red Hat Enterprise Linux 10 — A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framewor… 2026-07-21 CVE-2026-15812 MEDIUM 4.8 Red Hat Enterprise Linux 10 — A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: … 2026-07-21 CVE-2026-15927 MEDIUM 6.8 Red Hat Quay 3.1 — A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in… 2026-07-21 CVE-2026-16445 HIGH 7.5 Red Hat Enterprise Linux 8 — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by provid… 2026-07-21 CVE-2026-16461 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcin… 2026-07-21 CVE-2026-16493 HIGH 7.8 Red Hat Ansible Automation Platform 2 — A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artif… 2026-07-21 CVE-2026-16517 LOW 2.9 Red Hat Hardened Images — A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header … 2026-07-21 CVE-2026-59842 LOW 3.7 Red Hat Enterprise Linux 10 — A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key sh… 2026-07-21 CVE-2026-59843 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CH… 2026-07-21 CVE-2026-59844 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily … 2026-07-21 CVE-2026-59845 MEDIUM 5.3 Red Hat Enterprise Linux 10 — A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID… 2026-07-21 CVE-2026-59846 LOW 3.9 Red Hat Enterprise Linux 10 — A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell… 2026-07-21 CVE-2026-59847 MEDIUM 5.9 Red Hat Enterprise Linux 10 — A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effe… 2026-07-21 CVE-2026-59848 MEDIUM 5.3 Red Hat Enterprise Linux 10 — A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh cli… 2026-07-21 CVE-2026-59849 LOW 3.1 Red Hat Enterprise Linux 10 — A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause li… 2026-07-21 CVE-2026-59850 MEDIUM 4.3 Red Hat Enterprise Linux 10 — A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks ca… 2026-07-21 CVE-2026-59851 HIGH 8.8 Red Hat Enterprise Linux 10 — A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify w… 2026-07-21 CVE-2026-12080 HIGH 7.3 Red Hat Enterprise Linux 10 — A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the g… 2026-07-20 CVE-2026-12701 CRITICAL 9 Red Hat Ansible Automation Platform 2.5 For Rhel 8 — A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that … 2026-07-20 CVE-2026-15588 MEDIUM 5.3 Red Hat Enterprise Linux 10 — A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gd…● PoC 2026-07-20 CVE-2026-15813 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34… 2026-07-20 CVE-2026-16242 CRITICAL 9.4 Multicluster Engine For Kubernetes 2.1 — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing li… 2026-07-20 CVE-2026-16254 MEDIUM 4.3 Red Hat Advanced Cluster Security 4 — A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can … 2026-07-20 CVE-2026-16277 MEDIUM 6.5 Red Hat Enterprise Linux 10 — A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service w… 2026-07-20 CVE-2026-64612 HIGH 7.5 Red Hat Enterprise Linux 10 — A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader wi… 2026-07-20 CVE-2026-15943 MEDIUM 5.5 Red Hat Build Of Keycloak — A flaw was found in the Keycloak keycloak-services component, which handles the management of identity provide… 2026-07-17 CVE-2026-16072 MEDIUM 4.9 Red Hat Build Of Keycloak — A flaw was found in the organization management component of Keycloak. A delegated administrator with permissi… 2026-07-17 CVE-2026-16089 MEDIUM 5.4 Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAu… 2026-07-17 CVE-2026-16093 MEDIUM 5.4 Red Hat Build Of Keycloak — Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requ… 2026-07-17 CVE-2026-16103 MEDIUM 4.3 Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-… 2026-07-17 CVE-2026-16104 MEDIUM 4.3 Red Hat Build Of Keycloak — A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the… 2026-07-17 CVE-2026-16106 MEDIUM 4.9 Red Hat Build Of Keycloak — A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue o… 2026-07-17 CVE-2026-16108 MEDIUM 4.3 Red Hat Build Of Keycloak — A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is r… 2026-07-17 CVE-2026-16118 HIGH 7.1 Xdgmime — A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line…● PoC 2026-07-17 CVE-2026-15945 MEDIUM 4.3 Red Hat Build Of Keycloak — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grai… 2026-07-16 CVE-2026-1609 HIGH 8.1 Keycloak — A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and… 2026-07-16 CVE-2026-23538 HIGH 7.5 Feast Feature Server — A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers … 2026-07-16