Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1Red Hat

High [CVE-2026-70463] Authorization bypass via `auth users` directive parsing

Authorization bypass via `auth users` directive parsing. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70463
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-70464] Denial of Service via handshake stall

Denial of Service via handshake stall. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-70464
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53795] Arbitrary file write via --temp-dir or --link-dest options

Arbitrary file write via --temp-dir or --link-dest options. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53795
Red Hat Enterprise Linux
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-53793] rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode

rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode. Red Hat rates this important (CVSS 7.4). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53793
Red Hat Enterprise Linux
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-53791] rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header

rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header. Red Hat rates this important (CVSS 7.4). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53791
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53790] rsync < 3.5.0 Command Injection via Multiple Code Paths

rsync < 3.5.0 Command Injection via Multiple Code Paths. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53790
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-53785] Arbitrary file write via path traversal in --relative mode

Arbitrary file write via path traversal in --relative mode. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53785
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-53784] Unauthorized File Access via Symlink Module Root

Unauthorized File Access via Symlink Module Root. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53784
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53783] Directory escape via TOCTOU race condition in rrsync

Directory escape via TOCTOU race condition in rrsync. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: rsync.

CVE-2026-53783
Red Hat Enterprise Linux
Aug 13, 2026
High7.0Red Hat

High [CVE-2026-53803] Local Privilege Escalation via Symlink Following

Local Privilege Escalation via Symlink Following. Red Hat rates this important (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.

CVE-2026-53803
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73508] Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names

Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: OpenShift Serverless; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 3 more.

CVE-2026-73508
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73507] Denial of Service via CPU Exhaustion in XmlFrameDecoder

Denial of Service via CPU Exhaustion in XmlFrameDecoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Single Sign-On 7.

CVE-2026-73507
Unclassified
Aug 13, 2026
High7.8Red Hat

High [CVE-2026-73505] Arbitrary command execution via template injection in directory names

Arbitrary command execution via template injection in directory names. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-73505
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server

Denial of Service via unbounded memory growth in QUIC server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56097 with package openssl-main-3.5.6-0.5.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: openssl.

CVE-2026-14456
Red Hat Enterprise Linux
Aug 13, 2026
High7.2Apache

High [CVE-2026-66256] ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig

- * UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2026-66256
Unclassified
Aug 13, 2026
High7.7Red Hat Updated

High [CVE-2026-66804] Authenticated SSRF via user-controlled towerHost in /ansibletower handler

Authenticated SSRF via user-controlled towerHost in /ansibletower handler. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:57194 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, multicluster-engine/console-mce-rhel9:1786668856. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66804
Unclassified
Aug 13, 2026
High7.2Red Hat Updated

High [CVE-2026-6471] Arbitrary code execution via logical decoding plugin

Arbitrary code execution via logical decoding plugin. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-6471
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-14671] Arbitrary code execution via type confusion in 'refint' module

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This could lead to a complete compromise of the database server. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14671
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat Updated

High [CVE-2026-6464] PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. During the `COPY FROM STDIN` operation, untrusted data can be mistakenly interpreted as psql commands if an error injection causes the command to fail prematurely. This could allow an attacker to achieve arbitrary command execution. Successful exploitation requires the attacker to control both the server and the data being copied, or to leverage a coincidental error while controlling only the data. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-829.

CVE-2026-6464
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat Updated

High [CVE-2026-19385] PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists

PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:57198 with package postgresql17-main-17.11-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-19385
Red Hat Enterprise Linux
Aug 13, 2026