Complete feed
Security advisories & CVEs
2709 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-19149] Sandbox escape via use-after-free vulnerability in Aura
Sandbox escape via use-after-free vulnerability in Aura. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-67422] Denial of Service via Regular Expression Vulnerability
Denial of Service via Regular Expression Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Hardened Images; Self-service automation portal 2.
High [CVE-2026-66808] unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)
unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection). Red Hat rates this important (CVSS 8.7). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/hypershift-addon-rhel9-operator:1786912006, multicluster-engine/hypershift-addon-rhel9-operator:1786548381, multicluster-engine/hypershift-addon-rhel9-operator:1787259113, multicluster-engine/hypershift-addon-rhel9-operator:1787264068. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-71436] Denial of Service via invalid X-Axis parameters
Denial of Service via invalid X-Axis parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
High [CVE-2026-71327] Cross-namespace backend hijacking due to Gateway API identity collision
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10. Its Kubernetes Gateway API provider incorrectly generates unique identifiers for routes and services. This vulnerability allows an attacker to create conflicting routes, which can then overwrite the backend services of another isolated environment (namespace). This could lead to unauthorized control over services in different namespaces. A flaw in Traefik's Kubernetes Gateway API provider allows a lower-privileged tenant to overwrite backend routing rules across namespace boundaries. Due to deterministic route identity generation concatenating namespace, route name, Gateway identity, entry point, and rule index using hyphens, identical generated string identifiers result in name collisions. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.
High [CVE-2026-71325] Namespace isolation bypass via TraefikService backendRef
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10. A flaw was found in Traefik. This flaw allows a tenant, even when restricted by Role-Based Access Control (RBAC) to a single namespace, to bypass namespace isolation. This defeats the intended `allowCrossNamespace=false` enforcement, leading to unauthorized access or manipulation of services across namespaces. A flaw in Traefik's service resolver allows a lower-privileged tenant to reference and bind cross-namespace TraefikService objects via @kubernetescrd, even when allowCrossNamespace=false is configured. By creating a custom router targeting an isolated TraefikService CRD in a separate namespace, an authenticated attacker can bypass namespace isolation controls, intercepting or rerouting backend service traffic across multi-tenant boundaries.
High [CVE-2026-43632] Potential code execution via a race condition in tokenization endpoints
Potential code execution via a race condition in tokenization endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-364.
High [CVE-2026-43631] Remote code execution via use-after-free vulnerability in llama-server
Remote code execution via use-after-free vulnerability in llama-server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825.
High [CVE-2026-43629] Arbitrary code execution via crafted KV cache state files
Arbitrary code execution via crafted KV cache state files. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-43627] Arbitrary Code Execution via Integer Overflow in Memory Allocation
Arbitrary Code Execution via Integer Overflow in Memory Allocation. Red Hat rates this important (CVSS 7.8). Weakness: CWE-805. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-7867] Local Privilege Escalation via as-user option spoofing
Local Privilege Escalation via as-user option spoofing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:53435 with package udisks2-0:2.11.0-2.el10_2.1. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-71498] Information disclosure via out-of-bounds read with malformed UTF-8 input
Information disclosure via out-of-bounds read with malformed UTF-8 input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-125.
Medium [CVE-2026-70631] Information disclosure via uninitialized heap memory read in TIFF decoder
Information disclosure via uninitialized heap memory read in TIFF decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-70630] Information disclosure via uninitialized heap memory read in Screenpresso decoder
Information disclosure via uninitialized heap memory read in Screenpresso decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824.
Medium [CVE-2026-70629] Information disclosure via uninitialized heap memory read in RSCC decoder
Information disclosure via uninitialized heap memory read in RSCC decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-71497] Cross-site scripting via malformed HTML tag names
Cross-site scripting via malformed HTML tag names. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-1289. Affected products named by the advisory: Cryostat 4; Migration Toolkit for Applications 8; OpenShift Developer Tools and Services; Red Hat AMQ Broker 7; and 12 more. Affected products named by the advisory: Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Quarkus Native builder; Red Hat Enterprise Linux 10; and 8 more.
Medium [CVE-2026-61632] Information disclosure via path traversal in b64 extension
Information disclosure via path traversal in b64 extension. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected products named by the advisory: Red Hat Developer Hub; Red Hat OpenShift Container Platform 4; Self-service automation portal 2.
Medium [CVE-2026-19167] Cross-origin data leakage via integer overflow in GPU
Cross-origin data leakage via integer overflow in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190.
Medium [CVE-2026-19146] Google Chrome (Android): Information disclosure via uninitialized GPU memory use
Google Chrome (Android): Information disclosure via uninitialized GPU memory use. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824.
Medium [CVE-2026-19139] OS-level privilege escalation due to a race condition via a malicious file
OS-level privilege escalation due to a race condition via a malicious file. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367.