Complete feed
Security advisories & CVEs
2749 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API
Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.
Low [CVE-2026-6469] Incorrect ownership assignment allows unauthorized statistics modification
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. The overall impact is limited, as standard DROP TABLE operations still correctly remove the affected objects. This flaw has a Low impact on Red Hat products. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-708. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Low [CVE-2026-16241] Denial of Service via integer underflow
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This vulnerability causes the client to overwrite a large memory region, leading to a temporary denial of service (DoS). This Low impact flaw in PostgreSQL ECPG affects client applications. The limited scope to client-side disruption and the prerequisite of elevated server privileges contribute to its lower severity. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Low [CVE-2026-14673] PostgreSQL amcheck: Privilege escalation via untrusted search path
PostgreSQL amcheck: Privilege escalation via untrusted search path. Red Hat rates this low (CVSS 3.8). Weakness: CWE-426. Red Hat lists fixing advisory RHSA-2026:54751 with package postgresql18-main-18.6-0.1.hum1, postgresql17-main-17.11-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations
Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.
Critical [CVE-2026-71471] Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image
Hub Search CR Collector. ImageOverride propagated to every spoke as arbitrary container image. Red Hat rates this important (CVSS 9). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-73501] ValidationHandler.Load Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler. Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0. This vulnerability allows a remote attacker to bypass authentication checks. Specifically, the system incorrectly handles missing authentication configurations, substituting them with a function that does not verify user credentials. This enables unauthorized access to protected resources that should require proper authentication, compromising the application's security. This Critical flaw in `kin-openapi` allows unauthenticated attackers to bypass API security enforcement in applications utilizing `ValidationHandler` without an explicitly configured authentication function.
Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)
hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*). Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-70398] GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace
GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace. Red Hat rates this important (CVSS 9.6). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-72526] pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation
pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation. Red Hat rates this important (CVSS 9.9). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-46382] Server-Side Request Forgery in import functionality
Server-Side Request Forgery in import functionality. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918.
High [CVE-2026-71469] Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS
Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-api-rhel9:1787191668, rhacm2/acm-search-v2-api-rhel9:1787263804, rhacm2/acm-search-v2-api-rhel9:1787238618, rhacm2/acm-search-v2-api-rhel9:1787229541. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-71473] addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke
addonfactory. GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke. Red Hat rates this important (CVSS 8.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-73500] Denial of Service via unbounded TLS handshake goroutines
Denial of Service via unbounded TLS handshake goroutines. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ansible Automation Platform 2; Red Hat Ceph Storage 5; and 11 more. Affected products named by the advisory: Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 7 more.
High [CVE-2026-19654] Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met: * imptcp module is explicitly loaded * There's an imptcp listener using the non-default framing.delimiter.regex mode * The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the `rsyslog` package as shipped with Red Hat Enterprise Linux Versions. Weakness: CWE-125.
High [CVE-2026-13622] virt-handler migration proxy follows symlinks allowing container escape to host
virt-handler migration proxy follows symlinks allowing container escape to host. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:53763 with package container-native-virtualization/virt-handler-rhel9:1786348529, container-native-virtualization/virt-handler-rhel9:1786309624, container-native-virtualization/virt-handler:1785837722, container-native-virtualization/virt-handler-rhel9:1786334215. Affected products named by the advisory: Red Hat Container Native Virtualization 4.12; Red Hat Container Native Virtualization 4.13; Red Hat Container Native Virtualization 4.14; Red Hat Container Native Virtualization 4.15; and 7 more. Affected products named by the advisory: Red Hat Container Native Virtualization 4.16; Red Hat Container Native Virtualization 4.17; Red Hat Container Native Virtualization 4.18; Red Hat Container Native Virtualization 4.19; and 3 more.
High [CVE-2026-73422] Arbitrary code execution via unescaped View Transition animation properties
Arbitrary code execution via unescaped View Transition animation properties. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-73415] Arbitrary code execution via malicious image in image viewer
Arbitrary code execution via malicious image in image viewer. Red Hat rates this important (CVSS 8). Weakness: CWE-911. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-18724] Stack buffer overflow in idbm record parsing
Stack buffer overflow in idbm record parsing. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: iscsi-initiator-utils.
High [CVE-2026-73122] auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces
auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces. Red Hat rates this important (CVSS 7.7). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-channel-rhel9:1787259310, rhacm2/multicluster-operators-channel-rhel9:1787242099, rhacm2/multicluster-operators-channel-rhel9:1787238600, rhacm2/multicluster-operators-channel-rhel9:1787260663. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.