VulniPulse uses Google Ads measurement to understand visits from advertisements and campaign performance. It runs cookie-free until you choose — accepting enables cookies for more accurate attribution. Rejecting keeps it cookie-free and never limits the site.
See exactly what is measuredComplete feed
Critical/high still unreviewed, or CISA KEV listed
Denial of Service via Regular Expression Denial of Service in linkify function. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333. Affected package(s): devspaces/openvsx-rhel9:1779528224. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`).
Out-of-bounds Write via Specially Crafted PSD Image. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected package(s): ansible-automation-platform, quay/quay-rhel9:1775069491, python3.12-pillow, rhaiis/model-opt-cuda-rhel9:1772713830, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1776318795. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`).
Denial of Service via malicious HTML file drag and drop in help system. Red Hat rates this important (CVSS 7.5). Weakness: CWE-237. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Out-of-bounds write in grayscale color transformation when using LCMS2. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary file overwrite and potential code execution via incomplete path sanitization. Red Hat rates this important (CVSS 7). Weakness: CWE-73. Affected package(s): busybox-main. Resolved in Red Hat advisory RHSA-2026:13831 — update the affected packages (`sudo dnf update`).
Arbitrary file modification and privilege escalation via unvalidated tar archive entries. Red Hat rates this important (CVSS 7). Weakness: CWE-73. Affected package(s): busybox-main. Resolved in Red Hat advisory RHSA-2026:13831 — update the affected packages (`sudo dnf update`).
Arbitrary code execution via insecure pickle deserialization. Red Hat rates this important (CVSS 7.6). Weakness: CWE-502. Affected package(s): rhoai/odh-kserve-agent-rhel9:1770754605. Resolved in Red Hat advisory RHSA-2026:3713 — update the affected packages (`sudo dnf update`).
ReDoS via $data reference. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): quay/quay-rhel9:1775069491, rhoai/odh-dashboard-rhel8:1774282136, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, automation-gateway, rhoai/odh-dashboard-rhel9:1779189627, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`).
cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves. Red Hat rates this important (CVSS 7.4). Weakness: CWE-354. Affected package(s): ansible-automation-platform, quay/quay-rhel9:1775069491, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, fence-agents, rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1776319190, rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1776318795. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`).
MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery. Red Hat rates this important (CVSS 7.7). Weakness: CWE-120. Affected package(s): munge, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:2934 — update the affected packages (`sudo dnf update`).
Insecure default configuration leads to local man-in-the-middle attacks on Windows. Red Hat rates this low (CVSS 7.8). Weakness: CWE-427. Affected package(s): libssh-main. Resolved in Red Hat advisory RHSA-2026:7067 — update the affected packages (`sudo dnf update`).
LIBPNG has a heap buffer overflow in png_set_quantize. Red Hat rates this important (CVSS 7). Weakness: CWE-125. Affected package(s): rhcos, libpng15, libpng, libpng12, java, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`).
Intel (R): From CVEorg collector. Red Hat rates this important (CVSS 7.9). Weakness: CWE-1220. Affected package(s): microcode_ctl. Resolved in Red Hat advisory RHSA-2026:6888 — update the affected packages (`sudo dnf update`).
Inappropriate implementation in WebGPU. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Heap buffer overflow in Codecs. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Arbitrary Code Execution via unsafe JSON Path expression evaluation. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected package(s): ansible-automation-platform, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`).
Axios affected by Denial of Service via __proto__ Key in mergeConfig. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected package(s): rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, ansible-automation-platform, openshift-service-mesh/kiali-ossmc-rhel9:1771372942, rhoai/odh-dashboard-rhel9:1776742021. Resolved in Red Hat advisory RHSA-2026:3107 — update the affected packages (`sudo dnf update`).
Unauthorized Access via JWT authorization grant with disabled users. Red Hat rates this important (CVSS 8.1). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released.
Disabled identity providers are still accepted for JWT Authorization Grant. Red Hat rates this important (CVSS 8.8). Weakness: CWE-358. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`).
Unauthorized organization registration via improper invitation token validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.13, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`).