VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Out-of-bounds read or write due to integer overflow in DIB coder. Red Hat rates this important (CVSS 8.1). Weakness: CWE-190. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:6713 — update the affected packages (`sudo dnf update`).
Denial of Service via uninitialized pointer dereference in JBIG decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:6713 — update the affected packages (`sudo dnf update`).
Server-Side Request Forgery bypass via inconsistent URL parsing. Red Hat rates this important (CVSS 7.1). Weakness: CWE-474. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`).
Arbitrary file read via improper path validation in `filestring()` function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`).
missing mapped-length guard after cpu_physical_memory_map causes host OOB write. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
TechDocs Mkdocs configuration key enables arbitrary code execution. Red Hat rates this important (CVSS 9.1). Weakness: CWE-791. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`).
hardlink path traversal via drive-relative linkpath. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Impersonation of servers or clients via reverse DNS spoofing. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): zookeeper, rhoai/odh-modelmesh-rhel9:1776756834. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`).
Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1389. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1774268173, devspaces/openvsx-rhel9:1779528224. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`).
Signature verification bypass via malicious JWT allows unauthorized access. Red Hat rates this important (CVSS 9.1). Weakness: CWE-347. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1773771962, quay/quay-rhel9:1779204086, quay/quay-rhel8:1773971077, quay/quay-rhel8:1773936323, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`).
Denial of Service via malformed RTP payload processing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Incorrect parsing of IPv6 host literals in net/url. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift-service-mesh/istio-cni-rhel8:1777374598, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-oauth-server-rhel9:1779253952, openshift4/ose-tests:1777002345. Resolved in Red Hat advisory RHSA-2026:11749 — update the affected packages (`sudo dnf update`).
Incorrect enforcement of email constraints in crypto/x509. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected package(s): rhc-worker-playbook, golang1, golang, openshift-gitops, rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator:1.0.2, delve. Resolved in Red Hat advisory RHSA-2026:28047 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via Prototype Pollution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1776151134, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, openshift4/ose-networking-console-plugin-rhel9:1778517109. Resolved in Red Hat advisory RHSA-2026:9848 — update the affected packages (`sudo dnf update`).
Remote Code Execution via insecure callback function implementation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via malicious functions in user-writable schemas during extension upgrade. Red Hat rates this important (CVSS 8.8). Weakness: CWE-427. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
DNS access control bypass due to plugin execution order flaw. Red Hat rates this important (CVSS 7.7). Weakness: CWE-367. Affected package(s): rhacm2/lighthouse-coredns-rhel9:1774086225, rhacm2/lighthouse-agent-rhel9:1780204232, rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:8151 — update the affected packages (`sudo dnf update`).
Denial of Service vulnerability due to predictable pseudo-random number generation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1241. Affected package(s): rhacm2/lighthouse-coredns-rhel9:1774086225, rhacm2/lighthouse-agent-rhel9:1780204232, rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:8151 — update the affected packages (`sudo dnf update`).
Denial of Service via XML entity expansion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, rhoai/odh-dashboard-rhel8:1774282136, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, automation-gateway. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`).
Denial of Service via excessive JSON nesting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.