Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-72815] go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls
go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:49718 with package prometheus3-13-main-3.13.2-0.2.hum1, cosign-main-3.1.3-0.1.hum1, spire1-14-main-1.14.7-0.4.hum1, spire1-15-main-1.15.2-0.4.hum1. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; Migration Toolkit for Applications 8; and 12 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Edge Manager 1; and 8 more.
Medium [CVE-2026-72814] Information Disclosure via relative path traversal
Information Disclosure via relative path traversal. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Update Service.
Medium [CVE-2025-71405] Open Redirect vulnerability via RedirectSlashes middleware
Open Redirect vulnerability via RedirectSlashes middleware. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-601.
Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser
Denial of Service via uncontrolled recursion in config parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-45205] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 on Linux and Unix are susceptible to a vulnerability in commons-configuration2-2.10.1. Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.
Medium [CVE-2026-58084] FreeBSD Vulnerability in NetApp Products
FreeBSD versions 15.1 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user who can obtain uninitialized kernel stack memory by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2) disclose sensitive kernel data. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp states there is no workaround available at this time.
Low [CVE-2026-63650] User misidentification via ignored X.509 identity field
User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.
Critical [CVE-2026-73653] Browser Mode provider commands bypass the file-access permission gate
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API can read arbitrary local files, create or overwrite image and trace files, or delete files accessible to the Vitest process even when allowWrite is false. A flaw was found in Vitest. A remote attacker, by sending specially crafted commands to the Browser Mode API, could bypass file access restrictions. This allows the attacker to read, create, overwrite, or delete arbitrary files on the system where Vitest is running, even when file write permissions are explicitly disabled. Red Hat severity: Critical — CVSS 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-22. Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop. Red Hat lists Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Trusted Artifact Signer as not affected.
High [CVE-2026-73417] Cross-site scripting (XSS) allows arbitrary code execution
Cross-site scripting (XSS) allows arbitrary code execution. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-56860] golang net/url: Denial of Service from quadratic complexity in path resolution
golang net/url: Denial of Service from quadratic complexity in path resolution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-56853] Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6, grafana-0:9.2.10-33.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-56858] Go html/template: Cross-Site Scripting via pathological input
Go html/template: Cross-Site Scripting via pathological input. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:59566 with package rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6, grafana-0:9.2.10-33.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
High [CVE-2026-56862] Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-56865] Supply chain compromise via transparency log tile verification bypass
Supply chain compromise via transparency log tile verification bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-347.
High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue
Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59566 with package golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.3, rhdh/rhdh-rhel9-operator:1788278786, golang1-25-main-1.25.13-0.1.hum1, osbuild-composer-0:101.3-4.el9_4.6. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator
FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.
High [CVE-2026-45774] Arbitrary file read via path traversal in profile import
Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism
Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-48099] Filesystem path traversal via encoded dot segments
Filesystem path traversal via encoded dot segments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22.