Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

302 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low2.7Red Hat

Low [CVE-2026-9088] Information disclosure due to user profile permission bypass

Information disclosure due to user profile permission bypass. Red Hat rates this low (CVSS 2.7). Weakness: CWE-1220. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9088
Unclassified
Jun 5, 2026
Low3.4Red Hat

Low [CVE-2026-8970] Privilege escalation in the Security component

Privilege escalation in the Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8970
Unclassified
May 19, 2026
Low3.4Red Hat

Low [CVE-2026-8968] Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8968
Unclassified
May 19, 2026
Low3.4Red Hat

Low [CVE-2026-8962] Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-358. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8962
Unclassified
May 19, 2026
Low3.4Red Hat

Low [CVE-2026-8961] Spoofing issue in the Form Autofill component

Spoofing issue in the Form Autofill component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-472. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8961
Unclassified
May 19, 2026
Low3.7Red Hat

Low [CVE-2026-43514] Information disclosure via AJP secret timing discrepancy

Information disclosure via AJP secret timing discrepancy. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Affected package(s): tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43514
Unclassified
May 12, 2026
Low2.2Red Hat

Low [CVE-2026-44927] Data integrity issue due to pointer truncation

Data integrity issue due to pointer truncation. Red Hat rates this low (CVSS 2.2). Weakness: CWE-681. Affected package(s): uriparser-main. Resolved in Red Hat advisory RHSA-2026:16341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-44927
Unclassified
May 8, 2026
Low3.7Red Hat

Low [CVE-2026-3832] Security bypass allows acceptance of revoked server certificates via crafted OCSP response

Security bypass allows acceptance of revoked server certificates via crafted OCSP response. Red Hat rates this low (CVSS 3.7). Weakness: CWE-179. Affected package(s): gnutls-main, rhui5/haproxy-rhel9:1781525671, gnutls, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Hardened Images; and 3 more.

CVE-2026-3832
Unclassified
Apr 30, 2026
Low3.7Red Hat

Low [CVE-2026-6276] Information disclosure due to cookie leak when reusing connections with custom Host headers

Information disclosure due to cookie leak when reusing connections with custom Host headers. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:12916 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6276
Unclassified
Apr 29, 2026
Low3.7Red Hat

Low [CVE-2026-5419] Information disclosure via timing side-channel in PKCS#7 padding removal

Information disclosure via timing side-channel in PKCS#7 padding removal. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Affected package(s): rhui5/haproxy-rhel9:1781525671, gnutls, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Discovery 2; and 4 more.

CVE-2026-5419
Unclassified
Apr 29, 2026
Low3.3Red Hat

Low [CVE-2026-41990] Denial of Service or data integrity issues from missing bounds check during Dilithium signing.

Denial of Service or data integrity issues from missing bounds check during Dilithium signing.. Red Hat rates this low (CVSS 3.3). Weakness: CWE-787. Affected package(s): libgcrypt-main. Resolved in Red Hat advisory RHSA-2026:8466 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41990
Unclassified
Apr 23, 2026
Low2.5Red Hat

Low [CVE-2026-6842] Nano: nano: local attacker can inject malicious.desktop launcher due to insecure directory permissions

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed. This issue affects Red Hat Enterprise Linux 8 and 9. Red Hat severity: Low — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-732. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: nano.

CVE-2026-6842
Red Hat Enterprise Linux
Apr 22, 2026
Low3.7Red Hat

Low [CVE-2026-22008] Improved Arena allocations (Oracle CPU 2026-04)

Improved Arena allocations (Oracle CPU 2026-04). Red Hat rates this low (CVSS 3.7). Weakness: CWE-122. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:9694 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-22008
Unclassified
Apr 21, 2026
Low2.9Red Hat

Low [CVE-2026-22007] Enhance crypto algorithm support (Oracle CPU 2026-04)

Enhance crypto algorithm support (Oracle CPU 2026-04). Red Hat rates this low (CVSS 2.9). Weakness: CWE-327. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-22007
Unclassified
Apr 21, 2026
Low3.7Red Hat

Low [CVE-2026-22018] Enhance Zip file reading (Oracle CPU 2026-04)

Enhance Zip file reading (Oracle CPU 2026-04). Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-22018
Unclassified
Apr 21, 2026
Low2.9Red Hat

Low [CVE-2026-34268] Enhance key generation (Oracle CPU 2026-04)

Enhance key generation (Oracle CPU 2026-04). Red Hat rates this low (CVSS 2.9). Weakness: CWE-327. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-34268
Unclassified
Apr 21, 2026
Low3.4Red Hat

Low [CVE-2026-6776] Incorrect boundary conditions in the WebRTC: Networking component

Incorrect boundary conditions in the WebRTC: Networking component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-131. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-6776
Unclassified
Apr 21, 2026
Low2.7Red Hat

Low [CVE-2026-22001] Information Schema unspecified vulnerability (CPU Apr 2026)

Information Schema unspecified vulnerability (CPU Apr 2026). Red Hat rates this low (CVSS 2.7). Weakness: CWE-538. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-22001
Unclassified
Apr 21, 2026
Low3.7Red Hat

Low [CVE-2026-41080] Denial of Service via hash flooding with crafted XML

Denial of Service via hash flooding with crafted XML. Red Hat rates this low (CVSS 3.7). Weakness: CWE-331. Affected package(s): expat-main. Resolved in Red Hat advisory RHSA-2026:11004 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41080
Unclassified
Apr 16, 2026
Low3.8Red Hat

Low [CVE-2026-33948] Input validation bypass via embedded NUL bytes allows parser differential attacks

Input validation bypass via embedded NUL bytes allows parser differential attacks. Red Hat rates this low (CVSS 3.8). Weakness: CWE-170. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33948
Unclassified
Apr 13, 2026