Redhat
81 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-74240
MEDIUM 5.4
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sig…
2026-08-14
CVE-2026-74241
MEDIUM 4.8
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handli…
2026-08-14
CVE-2026-74242
MEDIUM 5.3
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notifica…
2026-08-14
CVE-2026-74243
MEDIUM 6.5
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unaut…
2026-08-14
CVE-2026-74244
MEDIUM 5.9
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticate…
2026-08-14
CVE-2026-74245
MEDIUM 5.9
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID cou…
2026-08-14
CVE-2026-74247
MEDIUM 4.2
Red Hat Openshift Update Service — A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can ex…
2026-08-14
CVE-2026-13367
HIGH 7.8
Informix Dynamic Server — IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit s…
2026-08-12
CVE-2026-13476
HIGH 7.3
Informix Dynamic Server — IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary co…
2026-08-12
CVE-2026-73433
MEDIUM 6.6
Gst Plugins Good — A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk…
2026-08-12
CVE-2026-73434
MEDIUM 6.1
Gst Plugins Good — A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of a…
2026-08-12
CVE-2026-59087
HIGH 7.8
Red Hat Enterprise Linux 6 — A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader…● PoC
2026-08-10
CVE-2026-59088
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when process…
2026-08-10
CVE-2026-59090
HIGH 8.4
Red Hat Enterprise Linux 6 — A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `b…● PoC
2026-08-10
CVE-2026-59091
HIGH 7.3
Red Hat Enterprise Linux 6 — A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could…
2026-08-10
CVE-2026-18967
MEDIUM 6.4
Red Hat Build Of Keycloak — A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When co…
2026-08-06
CVE-2026-15572
HIGH 8.8
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Prot…
2026-08-05
CVE-2026-15573
HIGH 8.1
Red Hat Build Of Keycloak 26.4 — A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to…
2026-08-05
CVE-2026-16071
MEDIUM 5.4
Red Hat Build Of Keycloak 26.4 — A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from exte…
2026-08-05
CVE-2026-16100
MEDIUM 6.5
Red Hat Build Of Keycloak 26.6 — A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records…
2026-08-05
CVE-2026-16102
HIGH 8.1
Red Hat Build Of Keycloak 26.4 — A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access manage…
2026-08-05
CVE-2026-16442
HIGH 7.4
Red Hat Build Of Keycloak 26.4 — A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and use…
2026-08-05
CVE-2026-16443
HIGH 7.4
Red Hat Build Of Keycloak 26.4 — A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the co…
2026-08-05
CVE-2026-71225
MEDIUM 6.5
Libkcapi — A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 Ki…
2026-08-05
CVE-2026-71226
HIGH 7.3
Libkcapi — Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error befor…
2026-08-05
CVE-2026-71227
MEDIUM 5.1
Libkcapi — A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/O…
2026-08-05
CVE-2026-18569
LOW 3.7
Red Hat Build Of Keycloak — A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the R…
2026-08-04
CVE-2026-68743
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_to…
2026-08-04
CVE-2026-68744
LOW 3.3
Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply…
2026-08-04
CVE-2026-18477
MEDIUM 4.4
Red Hat Hardened Images — A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows…
2026-08-03
CVE-2026-18508
MEDIUM 4.4
Red Hat Hardened Images — A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are …
2026-08-03
CVE-2026-18651
MEDIUM 5.4
Red Hat Directory Server 11 — A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-lev…
2026-08-03
CVE-2026-68742
MEDIUM 5.5
Red Hat Enterprise Linux 10 — A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate th…
2026-08-03
CVE-2026-6695
MEDIUM 5.5
Red Hat Enterprise Linux 6 — A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially cra…
2026-08-03
CVE-2026-18570
MEDIUM 5.4
Red Hat Build Of Keycloak — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. Thi…
2026-08-02
CVE-2026-18571
MEDIUM 6.6
Red Hat Build Of Keycloak — A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) i…
2026-08-02
CVE-2026-18572
MEDIUM 6.5
Red Hat Build Of Keycloak — Keycloak provides authorization services that allow administrators to restrict access to resources based on ti…
2026-08-02
CVE-2026-18573
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and…
2026-08-02
CVE-2026-11770
HIGH 7.5
Red Hat Directory Server 11.7 E4s For Rhel 8 — A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters in…
2026-07-31
CVE-2026-15722
HIGH 7.5
Red Hat Directory Server 11.7 E4s For Rhel 8 — A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval()…
2026-07-31
CVE-2026-16105
MEDIUM 4.9
Red Hat Build Of Keycloak — A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-bas…
2026-07-31
CVE-2026-18203
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution.…
2026-07-31
CVE-2026-18206
LOW 3.7
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management…
2026-07-31
CVE-2026-18208
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an o…
2026-07-31
CVE-2026-18209
LOW 3.4
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentic…
2026-07-31
CVE-2026-18211
MEDIUM 4.2
Red Hat Build Of Keycloak — A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This componen…
2026-07-31
CVE-2026-18214
MEDIUM 6.8
Red Hat Build Of Keycloak — Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific …
2026-07-31
CVE-2026-18215
MEDIUM 6.8
Red Hat Build Of Keycloak — Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific or…
2026-07-31
CVE-2026-18217
LOW 3.4
Red Hat Build Of Keycloak — A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access managemen…
2026-07-31
CVE-2026-18218
MEDIUM 4.2
Red Hat Build Of Keycloak — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administra…
2026-07-31
CVE-2026-18378
HIGH 7.6
Cost Management Metrics Operator — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows u…
2026-07-30
CVE-2026-18381
HIGH 7.6
Cost Management Metrics Operator — A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfi…
2026-07-30
CVE-2026-18382
MEDIUM 6.8
Cost Management Metrics Operator — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a…
2026-07-30
CVE-2026-18201
MEDIUM 5.5
Red Hat Build Of Keycloak — Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw …
2026-07-29
CVE-2026-18207
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system chec…
2026-07-29
CVE-2026-66757
MEDIUM 5.5
Gimp — A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin alloc…● PoC
2026-07-27
CVE-2026-66758
HIGH 7.8
Gimp — A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates mem…
2026-07-27
CVE-2026-66759
HIGH 7.1
Gimp — A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processi…● PoC
2026-07-27
CVE-2026-17048
MEDIUM 5.5
Red Hat Build Of Keycloak 26.6 — A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issu…
2026-07-24
CVE-2026-17059
MEDIUM 6.5
Red Hat Build Of Keycloak — A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of t…
2026-07-24
CVE-2026-15370
MEDIUM 6.7
Red Hat Enterprise Linux 10 — A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsaf…
2026-07-21
CVE-2026-59842
LOW 3.7
Red Hat Enterprise Linux 10 — A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key sh…
2026-07-21
CVE-2026-59843
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CH…
2026-07-21
CVE-2026-59844
MEDIUM 6.5
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily …
2026-07-21
CVE-2026-59845
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID…
2026-07-21
CVE-2026-59846
LOW 3.9
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell…
2026-07-21
CVE-2026-59847
MEDIUM 5.9
Red Hat Enterprise Linux 10 — A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effe…
2026-07-21
CVE-2026-59848
MEDIUM 5.3
Red Hat Enterprise Linux 10 — A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh cli…
2026-07-21
CVE-2026-59849
LOW 3.1
Red Hat Enterprise Linux 10 — A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause li…
2026-07-21
CVE-2026-59850
MEDIUM 4.3
Red Hat Enterprise Linux 10 — A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks ca…
2026-07-21
CVE-2026-59851
HIGH 8.8
Red Hat Enterprise Linux 10 — A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify w…
2026-07-21
CVE-2026-15943
MEDIUM 5.5
Red Hat Build Of Keycloak — A flaw was found in the Keycloak keycloak-services component, which handles the management of identity provide…
2026-07-17
CVE-2026-16072
MEDIUM 4.9
Red Hat Build Of Keycloak — A flaw was found in the organization management component of Keycloak. A delegated administrator with permissi…
2026-07-17
CVE-2026-16089
MEDIUM 5.4
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAu…
2026-07-17
CVE-2026-16093
MEDIUM 5.4
Red Hat Build Of Keycloak — Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requ…
2026-07-17
CVE-2026-16103
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-…
2026-07-17
CVE-2026-16104
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the…
2026-07-17
CVE-2026-16106
MEDIUM 4.9
Red Hat Build Of Keycloak — A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue o…
2026-07-17
CVE-2026-16108
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is r…
2026-07-17
CVE-2026-15945
MEDIUM 4.3
Red Hat Build Of Keycloak — A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grai…
2026-07-16
CVE-2026-1609
HIGH 8.1
Keycloak — A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and…
2026-07-16