Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.2Red Hat

Medium [CVE-2026-32327] Denial of Service via XML stack recursion attack

Denial of Service via XML stack recursion attack. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:58474 with package apr-util-main-1.6.5-1.hum1.

CVE-2026-32327
Unclassified
Aug 6, 2026
Medium4.2Red Hat

Medium [CVE-2026-57818] Authorization Code Replay via Race Condition

Authorization Code Replay via Race Condition. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-57818
Unclassified
Aug 6, 2026
Medium5.3Red Hat

Medium [CVE-2026-68079] Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider

Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-613. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-68079
Unclassified
Aug 6, 2026
Medium5.4Red Hat

Medium [CVE-2026-68481] Revocation bypass allows unauthorized access

Revocation bypass allows unauthorized access. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-68481
Unclassified
Aug 6, 2026
Medium6.4Red Hat

Medium [CVE-2026-18967] SAML OneTimeUse assertion replay in IdP-Initiated broker flow

SAML OneTimeUse assertion replay in IdP-Initiated broker flow. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-294. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-18967
Unclassified
Aug 6, 2026
Low3.8Red Hat

Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision

Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.

CVE-2026-71326
Unclassified
Aug 6, 2026
Low3.7Red Hat

Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation

Authorization Code Substitution via missing c_hash validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-57817
Unclassified
Aug 6, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-10090] namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription

namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription. Red Hat rates this important (CVSS 9). Weakness: CWE-267. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat Advanced Cluster Management for Kubernetes 2.11; and 2 more.

CVE-2026-10090
Unclassified
Aug 5, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-10059] namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token

namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token. Red Hat rates this important (CVSS 9.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:59557 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1787259011, multicluster-engine/cluster-curator-controller-rhel9:1787201612. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-10059
Unclassified
Aug 5, 2026
High8.0Red Hat

High [CVE-2026-71312] Server-Side Command Execution via Malicious SFTP Filenames

Server-Side Command Execution via Malicious SFTP Filenames. Red Hat rates this important (CVSS 8). Weakness: CWE-78.

CVE-2026-71312
Unclassified
Aug 5, 2026
High7.6Red Hat

High [CVE-2026-34966] Information disclosure via Server-Side Request Forgery (SSRF) bypass

Information disclosure via Server-Side Request Forgery (SSRF) bypass. Red Hat rates this important (CVSS 7.6). Weakness: CWE-918.

CVE-2026-34966
Unclassified
Aug 5, 2026
High8.1Red Hat

High [CVE-2026-71309] Backend Root Escape via Incomplete Path Validation

Backend Root Escape via Incomplete Path Validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22.

CVE-2026-71309
Unclassified
Aug 5, 2026
High8.8Red Hat

High [CVE-2026-70428] Arbitrary file write via path traversal

Arbitrary file write via path traversal. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:60250 with package ocp-tools-4/jenkins-rhel8:1786533565, ocp-tools-4/jenkins-rhel9:1787124635, ocp-tools-4/jenkins-rhel9:1787124925, ocp-tools-4/jenkins-rhel9:1787125069. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-70428
Unclassified
Aug 5, 2026
High8.3Red Hat

High [CVE-2026-70426] Arbitrary code execution via deserialization filter bypass

Arbitrary code execution via deserialization filter bypass. Red Hat rates this important (CVSS 8.3). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:60250 with package ocp-tools-4/jenkins-rhel8:1786533565, ocp-tools-4/jenkins-rhel9:1787124635, ocp-tools-4/jenkins-rhel9:1787124925, ocp-tools-4/jenkins-rhel9:1787125069. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-70426
Unclassified
Aug 5, 2026
High8.8Red Hat

High [CVE-2026-70427] Arbitrary file write via crafted archives and symbolic links

Arbitrary file write via crafted archives and symbolic links. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:60250 with package ocp-tools-4/jenkins-rhel8:1786533565, ocp-tools-4/jenkins-rhel9:1787124635, ocp-tools-4/jenkins-rhel9:1787124925, ocp-tools-4/jenkins-rhel9:1787125069. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-70427
Unclassified
Aug 5, 2026
High8.8Red Hat

High [CVE-2026-15572] DCR protocol mapper type-swap policy bypass allows privilege escalation

DCR protocol mapper type-swap policy bypass allows privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.6-11. Affected products named by the advisory: Red Hat build of Keycloak 26.4.14; Red Hat build of Keycloak 26.6.5.

CVE-2026-15572
Unclassified
Aug 5, 2026
High7.4Red Hat

High [CVE-2026-16442] SAML IdP-initiated broker login bypasses link-only restriction

SAML IdP-initiated broker login bypasses link-only restriction. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.

CVE-2026-16442
Unclassified
Aug 5, 2026
High8.1Red Hat

High [CVE-2026-16102] Default DCR policy allows role forgery via User Property mappers

Default DCR policy allows role forgery via User Property mappers. Red Hat rates this important (CVSS 8.1). Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat Single Sign-On 7.

CVE-2026-16102
Unclassified
Aug 5, 2026
High8.1Red Hat

High [CVE-2026-15573] Authorization bypass via unnormalized URI matching in PathMatcher

Authorization bypass via unnormalized URI matching in PathMatcher. Red Hat rates this important (CVSS 8.1). Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk/keycloak-rhel9, keycloak-services. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat Data Grid 8; Red Hat Single Sign-On 7.

CVE-2026-15573
Unclassified
Aug 5, 2026
High7.4Red Hat

High [CVE-2026-16443] SAML broker metadata import disables response signature validation

SAML broker metadata import disables response signature validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.

CVE-2026-16443
Unclassified
Aug 5, 2026