Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-64579] preallocate inexact bins before xfrm_hash_rebuild reinsert
preallocate inexact bins before xfrm_hash_rebuild reinsert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64569] fix NULL deref in mpls_valid_fib_dump_req on CONFIG_INET=n
fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64574] tear down new links on vif update error path
tear down new links on vif update error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64567] reject free space cache with more entries than pages
reject free space cache with more entries than pages. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Medium [CVE-2026-64566] propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags
propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821.
Medium [CVE-2026-64571] validate RX frame length in p54_rx_eeprom_readback
validate RX frame length in p54_rx_eeprom_readback(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-64578] validate compound request size before reading StructureSize2
validate compound request size before reading StructureSize2. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-64575] fix double sock release on batch realloc
fix double sock release on batch realloc. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-64576] initialize extack in nh_res_bucket_migrate
initialize extack in nh_res_bucket_migrate(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-64570] fix fils_discovery double free on alloc failure
fix fils_discovery double free on alloc failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9.
Low [CVE-2026-18839] size_t underflow in singleOptionHelp
size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration
Privilege escalation via unrestricted object instantiation in project naming strategy configuration. Red Hat rates this low (CVSS 3.8). Weakness: CWE-502. Affected product named by the advisory: OpenShift Developer Tools and Services.
High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service
Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups
Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Red Hat lists fixing advisory RHSA-2026:59153 with package ansible-automation-platform-25/hub-rhel8:1787101922, ansible-automation-platform-26/lightspeed-rhel9:1787244079, python3.12-django-0:5.2.17-1.el8ap, ansible-automation-platform-25/lightspeed-rhel8:1787229385. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.
High [CVE-2026-68494] Denial of Service via incomplete fix in async JSON parser
Denial of Service via incomplete fix in async JSON parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53643 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, jackson-core. Affected products named by the advisory: Cryostat 4; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 28 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; and 24 more.
High [CVE-2026-42169] GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)
GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:50817 with package gimp-2:3.0.4-4.el9_8.9. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-56846] Remote memory exhaustion via HTTP/2 retained header blocks
Remote memory exhaustion via HTTP/2 retained header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:48305 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-42170] GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer (ddsread.c)
GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer() (ddsread.c). Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
High [CVE-2026-64561] Check for invalid/obsolete root *after* making MMU pages available
Check for invalid/obsolete root *after* making MMU pages available. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45192 with package kernel-0:5.14.0-687.30.1.el9_8, kernel-0:6.12.0-55.94.1.el10_0, kernel-0:4.18.0-553.147.1.el8_10, kernel-0:5.14.0-427.141.1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2026-51401] Arbitrary code execution via vms_fixfilename function
Arbitrary code execution via vms_fixfilename() function. Red Hat rates this important (CVSS 7.8). Weakness: CWE-641.