Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-19028] Denial of Service via integer underflow in Fletcher32 filter
Denial of Service via integer underflow in Fletcher32 filter. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images.
Medium [CVE-2026-19027] Information disclosure and denial of service via crafted HDF5 file
Information disclosure and denial of service via crafted HDF5 file. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-125.
Medium [CVE-2026-19026] Denial of service via crafted HDF5 file
Denial of service via crafted HDF5 file. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images.
Medium [CVE-2026-19025] Denial of Service due to malformed chunk data in files
Denial of Service due to malformed chunk data in files. Red Hat rates this moderate (CVSS 5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images.
Medium [CVE-2026-19024] Denial of service via malformed dataset
Denial of service via malformed dataset. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
Medium [CVE-2026-71313] Path Traversal allows arbitrary file write
Path Traversal allows arbitrary file write. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-22. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
Medium [CVE-2026-71311] FTP command injection via CRLF in filename encoding
FTP command injection via CRLF in filename encoding. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-93.
Medium [CVE-2026-71310] Denial of Service via unbounded HTTP CONNECT response headers
Denial of Service via unbounded HTTP CONNECT response headers. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
Medium [CVE-2026-70429] Privilege escalation via inconsistent case sensitivity in user and group names
Privilege escalation via inconsistent case sensitivity in user and group names. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:60250 with package ocp-tools-4/jenkins-rhel8:1786533565, ocp-tools-4/jenkins-rhel9:1787124635, ocp-tools-4/jenkins-rhel9:1787124925, ocp-tools-4/jenkins-rhel9:1787125069. Affected product named by the advisory: OpenShift Developer Tools and Services.
Medium [CVE-2026-49331] unauthenticated identity header injection on whitelisted paths
unauthenticated identity header injection on whitelisted paths. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-345. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-16100] Unbounded metric cardinality in user event metrics via request-controlled error text
Unbounded metric cardinality in user event metrics via request-controlled error text. Red Hat rates this moderate (CVSS 6.5). Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk/keycloak-rhel9-operator:26.6-11. Affected product named by the advisory: Red Hat build of Keycloak 26.6.
Medium [CVE-2026-16071] LDAP entry-DN user search bypasses configured users DN boundary
LDAP entry-DN user search bypasses configured users DN boundary. Red Hat rates this moderate (CVSS 5.4). Red Hat lists fixing advisory RHSA-2026:50848 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services. Affected products named by the advisory: Red Hat build of Keycloak 26.4.14; Red Hat build of Keycloak 26.6.5.
Medium [CVE-2026-71227] Infinite loop denial of service in libkcapi _kcapi_aio_read_all due to unhandled io_getevents timeout return
Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:56985 with package libkcapi-main-1.5.1-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-71225] IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-330. Red Hat lists fixing advisory RHSA-2026:56985 with package libkcapi-main-1.5.1-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-71201] Information disclosure via crafted request
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project. A project reader can exploit this vulnerability by sending a specially crafted request to the Ironic service. This allows the reader to access Portgroups that are assigned to Nodes belonging to or leased by other projects, leading to unauthorized information disclosure. This flaw has a moderate impact as OpenStack Ironic contains an authorization flaw in the Portgroups listing API. When a project-scoped reader lists portgroups by shard name, the service fails to apply the per-project ownership filter that it correctly applies on other listing paths, allowing the reader to enumerate portgroups belonging to nodes owned or leased by other projects. Exploitation requires valid project-reader credentials and knowledge of a target shard name, and discloses only portgroup metadata (no modification or availability impact), so the severity is limited to information disclosure across project boundaries. Red Hat OpenShift's baremetal (metal3) deployment runs Ironic as a single-tenant control-plane service and does not expose the multi-project reader RBAC path required for exploitation. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-639.
Medium [CVE-2026-67592] Denial of Service via uncontrolled incoming data transfers
Denial of Service via uncontrolled incoming data transfers. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat AMQ Clients.
Medium [CVE-2026-66277] Denial of Service via uncontrolled transfer frames
Denial of Service via uncontrolled transfer frames. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 2 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat JBoss Enterprise Application Platform Expansion Pack.
Medium [CVE-2026-66276] Denial of service via unbounded disposition range handling
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. All affected versions are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected Red Hat products: Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Quarkus; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-67591] Denial of Service via exceeding session flow control window
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. This can lead to a denial of service (DoS), making the system unavailable to legitimate users. The affected components are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Note: the substring-matched artifacts are ancillary (parent POM, test driver) — the core protonj2-client library was not found via strict search. The affects are precautionary. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat AMQ Broker 7. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66275] Denial of Service via exceeding session flow control window
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue. This action could lead to a denial of service (DoS), making the system unavailable to legitimate users. All affected versions are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Quarkus; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.