Complete feed
Security advisories & CVEs
302 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-24308] Information disclosure via improper handling of configuration values
Information disclosure via improper handling of configuration values. Red Hat rates this important (CVSS 3.3). Weakness: CWE-117. Affected package(s): zookeeper, rhoai/odh-modelmesh-rhel9:1776756834. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat build of Debezium 2; Red Hat build of Debezium 3; Red Hat Fuse 7; and 3 more.
Low [CVE-2026-27139] FileInfo can escape from a Root in golang os module
FileInfo can escape from a Root in golang os module. Red Hat rates this low (CVSS 2.5). Weakness: CWE-22. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-27138] Panic in name constraint checking for malformed certificates in crypto/x509
Panic in name constraint checking for malformed certificates in crypto/x509. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7291 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69645] Binutils objdump: Denial of Service via crafted DWARF debug information
Binutils objdump: Denial of Service via crafted DWARF debug information. Red Hat rates this low (CVSS 2.8). Weakness: CWE-1285. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69644] Denial of Service via crafted binary with malformed DWARF debug information
Denial of Service via crafted binary with malformed DWARF debug information. Red Hat rates this low (CVSS 2.8). Weakness: CWE-606. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69646] Denial of Service via malformed DWARF debug_rnglists data
Denial of Service via malformed DWARF debug_rnglists data. Red Hat rates this low (CVSS 2.8). Weakness: CWE-606. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69650] double free in readelf via crafted ELF binary with malformed relocation data
double free in readelf via crafted ELF binary with malformed relocation data. Red Hat rates this low (CVSS 3.3). Weakness: CWE-415. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69652] abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information
abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information. Red Hat rates this low (CVSS 3.3). Weakness: CWE-617. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69649] NULL pointer dereference in readelf via crafted ELF binary with malformed header fields
NULL pointer dereference in readelf via crafted ELF binary with malformed header fields. Red Hat rates this low (CVSS 3.3). Weakness: CWE-476. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-69651] Denial of Service via crafted ELF binary processing
Denial of Service via crafted ELF binary processing. Red Hat rates this low (CVSS 2.8). Weakness: CWE-824. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-11143] Security bypass due to differential URI parsing
Security bypass due to differential URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-444. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-2297] Logging Bypass in Legacy .pyc File Handling
Logging Bypass in Legacy.pyc File Handling. Red Hat rates this low (CVSS 3.3). Weakness: CWE-778. Affected package(s): python3.12, python3, python3.14, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19019 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Low [CVE-2025-12150] webauthn attestation statement verification bypass
A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration. Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
Low [CVE-2026-3184] Access control bypass due to improper hostname canonicalization
Access control bypass due to improper hostname canonicalization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-289. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.
Low [CVE-2026-2791] Mitigation bypass in the Networking: Cache component
Mitigation bypass in the Networking: Cache component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Low [CVE-2026-2790] Same-origin policy bypass in the Networking: JAR component
Same-origin policy bypass in the Networking: JAR component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Low [CVE-2026-2733] Missing Check on Disabled Client for Docker Registry Protocol
Missing Check on Disabled Client for Docker Registry Protocol. Red Hat rates this low (CVSS 3.8). Weakness: CWE-285. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-2366] Information disclosure via authorization bypass in Admin API
Information disclosure via authorization bypass in Admin API. Red Hat rates this low (CVSS 3.1). Weakness: CWE-639. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0965] Denial of Service via improper configuration file handling
Denial of Service via improper configuration file handling. Red Hat rates this low (CVSS 3.3). Weakness: CWE-73. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.
Low [CVE-2026-0967] Denial of Service via inefficient regular expression processing
Denial of Service via inefficient regular expression processing. Red Hat rates this low (CVSS 2.2). Weakness: CWE-1333. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.