VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Denial of Service via excessive JSON nesting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Denial of Service via heap use-after-free in event subscription. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Information disclosure due to case-insensitive Connection header processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-178. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`).
Denial of Service due to incomplete TLS handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`).
Denial of Service via multi-level nested syntax. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Affected package(s): rhaiis/vllm-cuda-rhel9:1774351144, rhaiis/model-opt-cuda-rhel9:1774547384, rhaiis/vllm-rocm-rhel9:1775252598, rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`).
Unauthorized access via improper validation of encrypted SAML assertions. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1287. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.14, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:3925 — update the affected packages (`sudo dnf update`).
Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login. Red Hat rates this important (CVSS 8.8). Weakness: CWE-305. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.14, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:3925 — update the affected packages (`sudo dnf update`).
Unauthorized authentication via disabled SAML Identity Provider. Red Hat rates this important (CVSS 8.1). Weakness: CWE-306. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.14, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:3925 — update the affected packages (`sudo dnf update`).
Improper Enforcement of Disabled Identity Provider in IdentityBrokerService (Authentication Bypass). Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`).
Denial of Service due to unreleased JDK Inflater from compressed HTTP requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): eap8-eap-product-conf-parent, eap8-wildfly, devspaces/openvsx-rhel9:1779528224, eap8-activemq-artemis, jetty-server, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`).
arbitrary file read via improper URL validation in multimodal inputs. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
denial of service via malformed HTML-like sequences. Red Hat rates this important (CVSS 8.2). Weakness: CWE-617. Affected package(s): rhdh/rhdh-hub-rhel9:1776784286, python3.12-markdown, rhoai/odh-training-rocm62-torch25-py311-rhel9:1776272253, automation-controller, rhdh/rhdh-hub-rhel9:1777903262, rhoai/odh-training-cuda124-torch25-py311-rhel9:1776243287. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`).
org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication. Red Hat rates this important (CVSS 9.1). Weakness: CWE-306. Affected package(s): eap8-activemq-artemis, artemis-server. Resolved in Red Hat advisory RHSA-2026:3955 — update the affected packages (`sudo dnf update`).
Unauthorized collection management operations due to improper access control. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege Escalation via Unauthorized Bulk Permission Update. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary file read via path traversal vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`).
Denial of Service via malformed requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`).
Docker CLI for Windows: Privilege escalation via malicious plugin binaries. Red Hat rates this important (CVSS 7.3). Weakness: CWE-427. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Privilege escalation or denial of service via use-after-free in nf_tables_addchain(). Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-416. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:10756 — update the affected packages (`sudo dnf update`).
Linux kernel (qla2xxx): Double free vulnerability leads to denial of service and potential privilege escalation.. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-672. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9870 — update the affected packages (`sudo dnf update`).