Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-69243] HTTP Request Smuggling via WebSocket Upgrade
HTTP Request Smuggling via WebSocket Upgrade. Red Hat rates this moderate (CVSS 7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54760 with package discovery/discovery-server-rhel9:1786638573. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Discovery 2; and 5 more.
High [CVE-2026-69192] Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this important (CVSS 8.6). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:56338 with package nodejs24-1:24.18.0-5.el10_2, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.2-0.1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-69185] Denial of Service via memory exhaustion from crafted packets
Denial of Service via memory exhaustion from crafted packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-69153] Information disclosure via crafted sourceMappingURL
Information disclosure via crafted sourceMappingURL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:56338 with package prometheus3-13-main-3.13.2-0.2.hum1, grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-14257 +1] DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56338 with package grafana12-4-main-12.4.6-0.4.hum1, grafana13-1-main-13.1.1-0.5.2.hum1, ansible-automation-platform/automation-portal:1787047114, nodejs22-main-22.23.2-2.3.2.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-69151] @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
@angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79.
High [CVE-2026-68945] @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache. Red Hat rates this important (CVSS 8.2). Weakness: CWE-694.
High [CVE-2026-12852] Bouncy Castle for Java: Denial of Service via MLS wire decoder
Bouncy Castle for Java: Denial of Service via MLS wire decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284.
High [CVE-2026-58062] Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response
Bouncy Castle for Java: Certificate validation bypass via stapled OCSP response. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.
High [CVE-2026-59650] Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value
Bouncy Castle for Java: Cryptographic key compromise due to unvalidated Diffie-Hellman peer value. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325.
High [CVE-2026-8763] Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI
Bouncy Castle for Java: Name Constraints bypass via trailing dot in rfc822Name and URI. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Clients; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7; Red Hat package: resteasy.
Medium [CVE-2026-69198] Server-Side Request Forgery (SSRF) and trust-boundary bypass
Server-Side Request Forgery (SSRF) and trust-boundary bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1389. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana12-4-main-12.4.6-0.3.hum1.
Medium [CVE-2026-18477] TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:49361 with package tar-main-1.35-9.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.
Medium [CVE-2026-18651] SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account
SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-287.
Medium [CVE-2026-18508] --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
- -one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:50807 with package tar-main-1.35-9.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more.
Medium [CVE-2026-68742] NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR
NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
Medium [CVE-2026-68743] PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1
PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation
Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.
Low [CVE-2026-18739] Off-by-one in poptStuffArgs
Off-by-one in poptStuffArgs. Red Hat rates this low (CVSS 2.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:56984 with package popt-main-1.19-11.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat Enterprise Linux 6.