Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-58428] Attachment allowlist bypass via web release edit form
Attachment allowlist bypass via web release edit form. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-434.
Medium [CVE-2026-58427] Information disclosure of private organization member lists
Information disclosure of private organization member lists. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-359. Affected product named by the advisory: OpenShift Pipelines.
Medium [CVE-2026-58417] Information disclosure via REST API exposes private organization membership
Information disclosure via REST API exposes private organization membership. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected product named by the advisory: OpenShift Pipelines.
Medium [CVE-2026-58416] Information disclosure via Fork-PR Actions task
Information disclosure via Fork-PR Actions task. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1220. Affected product named by the advisory: OpenShift Pipelines.
Medium [CVE-2026-57897] Information disclosure via Org-Level Actions Run/Job APIs
Information disclosure via Org-Level Actions Run/Job APIs. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1220. Affected product named by the advisory: OpenShift Pipelines.
Medium [CVE-2026-56657] Denial of Service in SSH Key Parser
Denial of Service in SSH Key Parser. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-42931] Denial of Service due to unbounded memory consumption in NPM package tag endpoint
Denial of Service due to unbounded memory consumption in NPM package tag endpoint. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-73559] Denial of Service via unbounded completion prompt lists
Denial of Service via unbounded completion prompt lists. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-73558] Cross-User Data Leakage via Integer Overflow
Cross-User Data Leakage via Integer Overflow. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-190.
Medium [CVE-2026-73557] Incomplete remediation allows bypass via concurrent prompt processing
Incomplete remediation allows bypass via concurrent prompt processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-73555] Information Disclosure via Validation Error Messages
Information Disclosure via Validation Error Messages. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-209. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-70453] Denial of Service via Algorithmic Complexity
Denial of Service via Algorithmic Complexity. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-70454] TLS Certificate Validation Bypass allows interception of encrypted sessions
TLS Certificate Validation Bypass allows interception of encrypted sessions. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-70462] Denial of Service via signed integer overflow in I/O timeout
Denial of Service via signed integer overflow in I/O timeout. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-53794] Denial of Service via --max-alloc=0 logic error
Denial of Service via --max-alloc=0 logic error. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-53792] Denial of Service via out-of-bounds read with crafted checksum block
Denial of Service via out-of-bounds read with crafted checksum block. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-129. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-73506] Terminal escape sequence injection via unsanitized prompt data
Terminal escape sequence injection via unsanitized prompt data. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-791.
Medium [CVE-2026-6470] Denial of Service via missing authorization in DDL commands
Denial of Service via missing authorization in DDL commands. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-18024] Information disclosure via buffer over-read in ascii function
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This could lead to limited information disclosure. This Moderate impact information disclosure flaw in PostgreSQL's `ascii()` SQL function allows an authenticated attacker to read up to 3 bytes of memory beyond an allocated buffer by providing a specially crafted text value. The limited scope of data disclosure contributes to its Moderate severity. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-126. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14681] Improper enforcement of GSSAPI encryption via direct TLS connection
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. A flaw was found in PostgreSQL. This enables the connection to proceed with only TLS encryption, even when GSSAPI is required. This Moderate severity flaw in PostgreSQL's GSSAPI support allows a remote, authenticated attacker with low privileges to bypass `pg_hba.conf` rules requiring GSSAPI encryption. By initiating a direct TLS connection, the attacker can force a less secure connection if TLS settings are more permissive, potentially compromising data integrity and confidentiality. The high attack complexity reduces the overall risk. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-924. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql18.