Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

302 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.1Red Hat

Low [CVE-2026-0968] Denial of Service due to malformed SFTP message

Denial of Service due to malformed SFTP message. Red Hat rates this low (CVSS 3.1). Weakness: CWE-476. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.

CVE-2026-0968
Unclassified
Feb 10, 2026
Low3.9Red Hat

Low [CVE-2026-1703] Information disclosure via path traversal when installing crafted wheel archives

Information disclosure via path traversal when installing crafted wheel archives. Red Hat rates this low (CVSS 3.9). Weakness: CWE-22. Affected package(s): python-pip-main. Resolved in Red Hat advisory RHSA-2026:7610 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1703
Unclassified
Feb 2, 2026
Low2.7Red Hat

Low [CVE-2025-13881] Limited administrator can retrieve sensitive user attributes via Admin API

Limited administrator can retrieve sensitive user attributes via Admin API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-266. Affected package(s): keycloak, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-13881
Unclassified
Jan 27, 2026
Low3.1Red Hat

Low [CVE-2026-1035] Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition

Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition. Red Hat rates this low (CVSS 3.1). Weakness: CWE-367. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1035
Unclassified
Jan 21, 2026
Low3.1Red Hat

Low [CVE-2026-1190] Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData

Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData. Red Hat rates this low (CVSS 3.1). Weakness: CWE-112. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1190
Unclassified
Jan 19, 2026
Low3.7Red Hat

Low [CVE-2026-0976] proxy bypass due to improper handling of matrix parameters in url paths

A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potentially bypassing proxy-level path filtering. This could expose administrative or sensitive endpoints that operators believe are not externally reachable. This vulnerability is rated Low for Red Hat Keycloak. The flaw arises from Keycloak's acceptance of RFC-compliant matrix parameters in URL paths, which can be mishandled by certain reverse proxy configurations. Exploitation depends on the specific reverse proxy configuration. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-20. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-0976
Unclassified
Jan 15, 2026
Low3.7Red Hat

Low [CVE-2026-0988] Denial of Service via Integer Overflow in g_buffered_input_stream_peek()

Denial of Service via Integer Overflow in g_buffered_input_stream_peek(). Red Hat rates this low (CVSS 3.7). Weakness: CWE-190. Affected package(s): glib2-main. Resolved in Red Hat advisory RHSA-2026:7461 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0988
Unclassified
Jan 15, 2026
Low3.7Red Hat

Low [CVE-2026-0989] Unbounded RelaxNG Include Recursion Leading to Stack Overflow

Unbounded RelaxNG Include Recursion Leading to Stack Overflow. Red Hat rates this low (CVSS 3.7). Weakness: CWE-674. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more.

CVE-2026-0989
Unclassified
Jan 15, 2026
Low2.9Red Hat

Low [CVE-2026-0992] Denial of Service via crafted XML catalogs

Denial of Service via crafted XML catalogs. Red Hat rates this low (CVSS 2.9). Weakness: CWE-400. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more.

CVE-2026-0992
Unclassified
Jan 15, 2026
Low3.7Red Hat

Low [CVE-2026-22036] Denial of Service via excessive decompression steps

Denial of Service via excessive decompression steps. Red Hat rates this low (CVSS 3.7). Weakness: CWE-770. Affected package(s): rhdh/rhdh-hub-rhel9:1780930740. Resolved in Red Hat advisory RHSA-2026:24841 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-22036
Unclassified
Jan 14, 2026
Low3.4Red Hat

Low [CVE-2026-0890] Spoofing issue in the DOM: Copy & Paste and Drag & Drop component

Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:1413 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-0890
Unclassified
Jan 13, 2026
Low3.7Red Hat

Low [CVE-2025-10939] unable to restrict access to the admin console

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed. Affected product named by the advisory: Red Hat build of Keycloak 26.4.

CVE-2025-10939
Unclassified
Oct 28, 2025
Low3.1Red Hat

Low [CVE-2025-11731] Libxslt: type confusion in exsltfuncresultcompfunction of libxslt

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service. The Red Hat Product Security team has rated this vulnerability as Low severity, given that exploitation only causes a crash and requires the processing of a specially crafted XSL stylesheet. There is no evidence of data corruption or code execution, but affected applications may experience denial-of-service conditions. Weakness: CWE-843. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:11015. Affected products named by the advisory: Red Hat package: libxslt.

CVE-2025-11731
Red Hat Enterprise Linux
Oct 14, 2025
Low3.1Red Hat

Low [CVE-2025-8277] Libssh: memory exhaustion via repeated key exchange in libssh

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability. The Red Hat Product Security team has assessed the severity of this vulnerability as Low.The issue requires an authenticated client to repeatedly initiate key exchanges with incorrect guesses, which leads to memory not being properly released. While this flaw can result in gradual memory exhaustion and potential denial of service (DoS) on the client side, it is not easily exploitable in typical usage scenarios and does not affect servers. The vulnerability does not compromise confidentiality or integrity and poses limited impact on system availability under normal operating conditions. Weakness: CWE-401. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:18683. Affected products named by the advisory: Red Hat package: libssh2.

CVE-2025-8277
Red Hat Enterprise Linux
Sep 9, 2025
Low3.7Red Hat

Low [CVE-2025-8283] Netavark: podman: netavark may resolve hostnames to unexpected hosts

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers. This vulnerability has been rated as having a Low security impact by the Red Hat Product Security team. For an attack to be successful, the attacker needs to have control over the domains used into the host's resolv.conf and have a prior knowledge about the hostnames and connections used by the running containers. Additionally, the attacker does not have full control over the amount or sensitivity of data sent by the container to the attacker controlled host and TLS validations may avoid the container to connect to the malicious domain. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-15.

CVE-2025-8283
Red Hat Enterprise Linux
Jul 28, 2025
Low3.6Red Hat

Low [CVE-2025-4878] Libssh: use of uninitialized variable in privatekey_from_file

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption. Red Hat Product Security has rated this vulnerability as having Low severity as the affected privatekey_from_file() function is deprecated and should not be used. Weakness: CWE-416. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:18683. Affected products named by the advisory: Red Hat package: libssh2.

CVE-2025-4878
Red Hat Enterprise Linux
Jul 22, 2025
Low2.5Red Hat

Low [CVE-2025-6170] stack buffer overflow in xmllint interactive shell command handling

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections. The Red Hat Product Security team has rated the severity of this vulnerability as Low, since it affects only the interactive shell mode of the xmllint tool and requires a user to manually run the tool and enter or receive specially crafted input. The exploitation requires local access and a highly specific usage scenario that is uncommon in typical environments. While it can cause a crash, the impact is limited to availability, and exploitation is unlikely in real-world deployments. Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Hardened Images; Red Hat Insights proxy 1.5; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat JBoss Core Services; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat package: libxml2.

CVE-2025-6170
Red Hat Enterprise Linux
Jun 16, 2025
Low3.9Red Hat

Low [CVE-2025-5918] Libarchive: reading past eof may be triggered for piped file streams

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition. This vulnerability is rated Low for Red Hat products. The flaw in libarchive can be triggered when processing specially crafted piped file streams with `bsdtar`, potentially leading to unpredictable program behavior or an application level denial-of-service condition. Exploitation requires user interaction to process a malicious archive. Red Hat severity: Low — CVSS 3.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libarchive.

CVE-2025-5918
Red Hat Enterprise Linux
Jun 9, 2025
Low2.8Red Hat

Low [CVE-2025-5917] Libarchive: off by one error in build_ustar_entry_name at archive_write_set_format_pax.c

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0. This vulnerability is rated Low for Red Hat products. While it could be a building block for more complex exploits, direct exploitation is limited. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libarchive.

CVE-2025-5917
Red Hat Enterprise Linux
Jun 9, 2025
Low3.9Red Hat

Low [CVE-2025-5916] Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c

A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0. This vulnerability is rated Low for Red Hat products as it requires a local attacker to provide a specially crafted WARC archive to an application using libarchive. Red Hat severity: Low — CVSS 3.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libarchive.

CVE-2025-5916
Red Hat Enterprise Linux
Jun 9, 2025