Complete feed
Security advisories & CVEs
3495 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-74636] Fix race between update_event_fields and, event_define_fields
Fix race between update_event_fields and, event_define_fields. Red Hat rates this low (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74627] prevent net-iov / page mixing
prevent net-iov / page mixing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-74687] prevent timer rearm during teardown
prevent timer rearm during teardown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-44517] Build breakout via malicious Git repository or tar archive
Build breakout via malicious Git repository or tar archive. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22. Affected products named by the advisory: Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 4 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Quay 3; Red Hat package: buildah; Red Hat package: podman.
Medium [CVE-2026-59296] Line-protocol and log injection via unsanitized input allows metric and log spoofing
Line-protocol and log injection via unsanitized input allows metric and log spoofing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 5 more.
Medium [CVE-2026-77679] path traversal in WebExtension XPI extraction (ZIP slip)
path traversal in WebExtension XPI extraction (ZIP slip). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22.
Medium [CVE-2026-55894] Denial of Service via crafted SH2A bytecode
Denial of Service via crafted SH2A bytecode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-77643] Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping
Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: xapian-core.
Medium [CVE-2026-53586] Information disclosure via HTTP redirect allows credential leakage
Information disclosure via HTTP redirect allows credential leakage. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Medium [CVE-2026-53583] Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison
Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Medium [CVE-2026-53585] Denial of Service via Unbounded Memory Allocation
Denial of Service via Unbounded Memory Allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Medium [CVE-2026-63379] HTTP header smuggling allows authorization bypass or cache poisoning
HTTP header smuggling allows authorization bypass or cache poisoning. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
Medium [CVE-2026-63380] Denial of Service via Null Pointer Dereference
Denial of Service via Null Pointer Dereference. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
Medium [CVE-2026-63381] Memory corruption due to use-after-free
Memory corruption due to use-after-free. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
Medium [CVE-2026-71492] Arbitrary file write via path traversal
Arbitrary file write via path traversal. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22.
Medium [CVE-2026-73199] NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value
NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
Medium [CVE-2026-73196] Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding
Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
Medium [CVE-2026-77014] Libsoup: libsoup: integer truncation in sort_ranges comparator causes silent omission of http range responses
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB. A remote attacker can exploit this to cause the server to silently omit requested byte ranges from responses. Exploitation requires the server to be serving resources larger than approximately 2 GB, which limits real-world impact. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-197. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3; Red Hat package: gnome-clocks; Red Hat package: podman.
Medium [CVE-2026-76957] Memory corruption vulnerability allows arbitrary code execution or denial of service
Memory corruption vulnerability allows arbitrary code execution or denial of service. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: expat; and 5 more.
Medium [CVE-2026-76956] Denial of Service via hash flooding attack with crafted XML
Denial of Service via hash flooding attack with crafted XML. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-331. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.