VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
2056 advisories across 32 monitored vendors.
Denial of Service via crafted request to get_password.php. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote code execution via invalid n_discard parameter in server endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): rhacm2/submariner-globalnet-rhel9:1774550347, oadp/oadp-velero-rhel9:1770421082, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845, rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1770103255, python3.12-urllib3, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1771502910. Resolved in Red Hat advisory RHSA-2026:2456 — update the affected packages (`sudo dnf update`).
pnpm code execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-693. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
pnpm Lockfile Integrity Bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-494. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution via buffer overflow in untgz utility. Red Hat rates this important (CVSS 8.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Host verification bypass during SSH transfers. Red Hat rates this low (CVSS 8.1). Weakness: CWE-358. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`).
Denial of Service via specially crafted POST request. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Affected package(s): ansible-automation-platform, rhaiis/vllm-cuda-rhel9:1774351144, rhoai/odh-caikit-nlp-rhel9:1780069094, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-vllm-cpu-rhel9:1776259063. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): automation-controller, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1771502844, ansible-automation-platform, rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1770053721, rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1770055428, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845. Resolved in Red Hat advisory RHSA-2026:2106 — update the affected packages (`sudo dnf update`).
jsPDF Local File Inclusion/Path Traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-73. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1770250889, advanced-cluster-security/rhacs-main-rhel8:1770074713, advanced-cluster-security/rhacs-main-rhel8:1769615659. Resolved in Red Hat advisory RHSA-2026:2568 — update the affected packages (`sudo dnf update`).
Cross-Site Scripting via untrusted user input. Red Hat rates this important (CVSS 7.2). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary code execution through malicious visualization definitions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service due to malformed NAVCOM packet parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:0770 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:1621 — update the affected packages (`sudo dnf update`).
Server-Side Request Forgery via header injection. Red Hat rates this important (CVSS 8.7). Weakness: CWE-93. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Remote Code Execution via insecure YAML deserialization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected package(s): rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`).
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform. Affected products named by the advisory: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0; Red Hat Runtimes Inventory Operator.
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 7 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 2 more.
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 12 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 7 more.
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 29 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 24 more.