Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2025-9615 +1] 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing WPA-Enterprise server validation bypass (incomplete fix for CVE-2025-9615)
802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing WPA-Enterprise server validation bypass (incomplete fix for CVE-2025-9615). Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: networkmanager.
High [CVE-2026-71366] notification backends allow SSRF and credential leakage
notification backends allow SSRF and credential leakage. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59153 with package automation-controller-0:4.7.16-1.el9ap, ansible-automation-platform-26/controller-rhel9:1787244009, automation-controller-0:4.6.32-1.el8ap, ansible-automation-platform-27/controller-rhel9:1787220257. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-71364] project archive extraction allows path traversal file writes
project archive extraction allows path traversal file writes. Red Hat rates this important (CVSS 7.2). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:59153 with package automation-controller-0:4.7.16-1.el9ap, ansible-automation-platform-26/controller-rhel9:1787244009, automation-controller-0:4.6.32-1.el8ap, ansible-automation-platform-27/controller-rhel9:1787220257. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-78367] rpmbuild getTarSpec crafted tar member name → macro injection
rpmbuild getTarSpec() crafted tar member name → macro injection. Red Hat rates this moderate (CVSS 7). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-78376] use-after-free of JSCValue function parameters
use-after-free of JSCValue function parameters. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-76848] Information disclosure via SQL injection in SelectQueryBuilder.distinctOn
Information disclosure via SQL injection in SelectQueryBuilder.distinctOn. Red Hat rates this important (CVSS 7.5). Weakness: CWE-89. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.
High [CVE-2026-76844] Information Disclosure via Path Traversal
Information Disclosure via Path Traversal. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; OpenShift Lightspeed; and 26 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat AMQ Broker 7; and 22 more.
High [CVE-2026-10582] Server-Side Request Forgery (SSRF) leading to information disclosure.
Server-Side Request Forgery (SSRF) leading to information disclosure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-918. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0.
High [CVE-2026-76172] URI parsing flaw enables server-side request forgery and redirects
URI parsing flaw enables server-side request forgery and redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-76. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-75975] Server-side request forgery via malformed IPv6 normalization
Server-side request forgery via malformed IPv6 normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-75899] Server-Side Request Forgery via repeated hostname percent-decoding
Server-Side Request Forgery via repeated hostname percent-decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-140. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-75931] Host confusion via skipped IDN canonicalization
Host confusion via skipped IDN canonicalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; and 29 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 25 more.
High [CVE-2026-78161] Out-of-bounds write in LECP CBOR Recording
Out-of-bounds write in LECP CBOR Recording. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787.
High [CVE-2026-52492] Arbitrary code execution via crafted TIFF image
Arbitrary code execution via crafted TIFF image. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.
High [CVE-2026-52490] Arbitrary code execution via process_command_opts function
Arbitrary code execution via process_command_opts() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.
Medium [CVE-2026-68516] Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset
Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787.
Medium [CVE-2026-17113] unvalidated image env var causes daemon crash
unvalidated image env var causes daemon crash. Red Hat rates this moderate (CVSS 6). Weakness: CWE-1287. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-75509] Issuer-validation bypass via array-valued claims
Issuer-validation bypass via array-valued claims. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-480. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux command line assistant; Red Hat OpenShift Virtualization 4; Red Hat Satellite 6.
Medium [CVE-2026-75099] Unauthenticated REST disclosure of certain content items in Apache Allura
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.
Medium [CVE-2025-27636 +5] Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers. In binary content mode the HTTP-header path filters Camel-internal headers through KnativeHttpHeaderFilterStrategy, but in structured content mode (Content-Type application/cloudevents+json) the CloudEvent extension fields are read directly from the JSON body and every extension key is copied into the Exchange headers without applying any HeaderFilterStrategy (CloudEventProcessors, spec versions 1.0, 1.0.1 and 1.0.2). As a result, an unauthenticated attacker can inject Camel-internal headers (e.g. CamelHttpUri, CamelHttpPath, CamelFileName) via a structured-mode CloudEvent request, matched case-insensitively against Camel's header map. When a route forwards messages from a Knative consumer to a header-driven component such as camel-http or camel-file, the injected headers override configured values, enabling server-side request forgery (SSRF), path traversal or message-dispatch redirection depending on the route.