Complete feed
Security advisories & CVEs
2749 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-53792] Denial of Service via out-of-bounds read with crafted checksum block
Denial of Service via out-of-bounds read with crafted checksum block. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-129. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-73506] Terminal escape sequence injection via unsanitized prompt data
Terminal escape sequence injection via unsanitized prompt data. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-791.
Medium [CVE-2026-6470] Denial of Service via missing authorization in DDL commands
Denial of Service via missing authorization in DDL commands. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-18024] Information disclosure via buffer over-read in ascii function
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This could lead to limited information disclosure. This Moderate impact information disclosure flaw in PostgreSQL's `ascii()` SQL function allows an authenticated attacker to read up to 3 bytes of memory beyond an allocated buffer by providing a specially crafted text value. The limited scope of data disclosure contributes to its Moderate severity. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-126. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14681] Improper enforcement of GSSAPI encryption via direct TLS connection
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. A flaw was found in PostgreSQL. This enables the connection to proceed with only TLS encryption, even when GSSAPI is required. This Moderate severity flaw in PostgreSQL's GSSAPI support allows a remote, authenticated attacker with low privileges to bypass `pg_hba.conf` rules requiring GSSAPI encryption. By initiating a direct TLS connection, the attacker can force a less secure connection if TLS settings are more permissive, potentially compromising data integrity and confidentiality. The high attack complexity reduces the overall risk. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-924. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql18.
Medium [CVE-2026-14678] Information disclosure via buffer over-read in pg_trgm
Information disclosure via buffer over-read in pg_trgm. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-126. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14672] User existence oracle in SCRAM authentication
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Unauthenticated attackers can verify if a specific user exists by observing the authentication iteration count, provided the targeted user is configured with a non-default scram_iterations value. A moderate-severity vulnerability in PostgreSQL allows unauthenticated attackers to enumerate valid users. By observing discrepancies in SCRAM authentication responses, attackers can identify users configured with a non-default scram_iterations count, which may facilitate targeted brute-force attacks. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-204. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14666] Row security caching disregards role modifications leading to unauthorized data access
Row security caching disregards role modifications leading to unauthorized data access. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-524. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14663] PostgreSQL pgcrypto: Information disclosure via cleartext storage with disabled ciphers
PostgreSQL pgcrypto: Information disclosure via cleartext storage with disabled ciphers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:54751 with package postgresql18-main-18.6-0.1.hum1, postgresql17-main-17.11-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; and 1 more.
Medium [CVE-2026-73584] Privileged file corruption and denial of service via insecure temporary file handling
Privileged file corruption and denial of service via insecure temporary file handling. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-377. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sblim-sfcb.
Medium [CVE-2026-73583] Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr
Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sblim-sfcb.
Medium [CVE-2026-73585] Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-377. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-73621] Arbitrary File Truncation via Commit.count Argument Injection
Arbitrary File Truncation via Commit.count() Argument Injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
Medium [CVE-2026-73619] Arbitrary file read vulnerability via `Repo.archive `
Arbitrary file read vulnerability via `Repo.archive()`. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
Medium [CVE-2026-19694] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-122.
Medium [CVE-2026-19695] Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-121.
Medium [CVE-2026-19696] Out-of-bounds Write in Wireshark
Out-of-bounds Write in Wireshark. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787.
Medium [CVE-2026-18728] Integer underflow in iscsiuio IPv4 DHCP parsing
Integer underflow in iscsiuio IPv4 DHCP parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-68454] Fix handling of AIF enable without AISB
Fix handling of AIF enable without AISB. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in
Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.