Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5Red Hat

Medium [CVE-2026-15943] OIDC IdP update reuses masked client secret after token URL change

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak reuses the existing real secret even if security-sensitive fields like the token URL have been changed, allowing an attacker to redirect and capture the secret. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires high administrative privileges to exploit. Successful exploitation allows an attacker to rebind and capture an OIDC client secret by modifying identity provider configuration fields. The vulnerability's root cause is the unconditional reuse of masked secrets during configuration updates without verifying if sensitive endpoint fields have changed. Weakness: CWE-1288. Affected Red Hat products: Red Hat Build of Keycloak. Red Hat lists Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15943
Unclassified
Jul 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-15945] Group hierarchy search discloses hidden parent groups under FGAP v2

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires an authenticated attacker with specific delegated administrative permissions and the non-default FGAP v2 feature to be enabled. Successful exploitation allows an attacker to disclose sensitive metadata and configuration details of parent groups they are otherwise restricted from viewing. The vulnerability's root cause is a failure to apply fine-grained access control filters to parent groups during hierarchical search result construction. Weakness: CWE-639. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15945
Unclassified
Jul 16, 2026
Low3.1Red Hat

Low [CVE-2026-47081] Information disclosure of mailbox existence via XAPPLEPUSHSERVICE command

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed. While no content is leaked, this constitutes an information disclosure regarding the existence and activity of other users' mailboxes. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-497. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47081
Red Hat Enterprise Linux
Jul 16, 2026
Low3.1Red Hat

Low [CVE-2026-47088] Information disclosure via heap exposure in MIME comment parsing

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user. By crafting an email message with a specially formed RFC 822 comment, the server could be made to read beyond the message's boundary in memory, potentially disclosing sensitive heap content to the attacker. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47088
Red Hat Enterprise Linux
Jul 16, 2026
Low3.5Red Hat

Low [CVE-2026-47087] Unauthorized access due to URLAUTH not honoring revoked authorizer access

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. This allows a previously authorized user to retain access via a URLAUTH URL, even after their authorization has been revoked, potentially leading to unauthorized information disclosure. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-613. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47087
Red Hat Enterprise Linux
Jul 16, 2026
High7.7Red Hat

High [CVE-2026-14251] Missing allowedNamespace check in ReconcilerHook for ClusterRole/Role cases enables potential privilege escalation and DoS

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H). Weakness: CWE-862. Affected Red Hat products: Red Hat OpenShift GitOps. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-14251
Unclassified
Jul 15, 2026
High8.8Red Hat

High [CVE-2026-30623] Remote code execution via unvalidated MCP server configuration

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process. A flaw was found in LiteLLM. This is possible because the application's MCP server creation functionality processes JSON configurations that can include unvalidated command and argument values. Successful exploitation could lead to a complete compromise of the affected system. Per the upstream advisory, exploitation requires authentication -- it is not reachable by a fully unauthenticated attacker -- but no further privilege beyond a working API key is needed to reach the vulnerable code path. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78. Red Hat lists Exploit Intelligence; Lightspeed Core; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI) as not affected.

CVE-2026-30623
Unclassified
Jul 15, 2026
High8.8Red Hat

High [CVE-2026-38974] Missing SSH host key verification allows potential impersonation

Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py. This vulnerability allows a remote attacker to impersonate a legitimate Git server. By doing so, the attacker could potentially intercept sensitive information or execute arbitrary code on the client system during a connection. Exploitation requires user interaction, specifically connecting to a malicious Git server. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-322. Affected Red Hat products: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4. Under investigation: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 7; Red Hat Satellite 6. Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-38974
Unclassified
Jul 15, 2026
Medium4.8Vendor: LowRed Hat

Medium [CVE-2026-15812] access control list bypass via link ID spoofing on unencrypted dynamic links

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities. Red Hat Product Security rates this vulnerability's impact as Low. Although the vulnerability allows an unauthenticated remote attacker to completely bypass the internal ACL layer and introduce arbitrary traffic, it depends entirely on a non-production configuration. The exploit requires that kronosnet actively accept connections from any arbitrary IP (dynamic links) while simultaneously running completely unencrypted traffic. Furthermore, this issue does not affect Red Hat Enterprise Linux High Availability (RHEL HA) or any official layered products, as Red Hat configurations securely enable network encryption by default, entirely mitigating the vulnerability's attack prerequisites.

CVE-2026-15812
Red Hat Enterprise Linux
Jul 15, 2026
Medium5.8Vendor: LowRed Hat

Medium [CVE-2026-15811] encryption key exposure in memory after cryptographic configuration changes

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability. Red Hat Product Security rates this flaw's impact as Moderate. While kronosnet is a critical core networking component within the Red Hat Enterprise Linux High Availability (RHEL HA) ecosystem, exploiting this vulnerability requires a high degree of complexity. An attacker must already possess local access to the host machine and successfully pair this flaw with a distinct memory disclosure mechanism to extract the key fragments post-free(). Red Hat severity: Low — CVSS 5.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Weakness: CWE-212. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15811
Red Hat Enterprise Linux
Jul 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15773] Use after free in Core

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the Core component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15773
Unclassified
Jul 14, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-15775] Insufficient policy enforcement in V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) An insufficient policy enforcement flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-346.

CVE-2026-15775
Unclassified
Jul 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-15774] Use after free in Skia

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15774
Unclassified
Jul 14, 2026
High8.8Red Hat

High [CVE-2026-15776] Type Confusion in V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A type confusion flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-843.

CVE-2026-15776
Unclassified
Jul 14, 2026
High8.8Red Hat

High [CVE-2026-15777] Use after free in UI

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the UI component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15777
Unclassified
Jul 14, 2026
High8.3Red Hat

High [CVE-2026-15772] Use after free in GPU

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-15772
Unclassified
Jul 14, 2026
High8.3Red Hat

High [CVE-2026-15769] Insufficient validation of untrusted input in Linux Toolkit Theming

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-807.

CVE-2026-15769
Unclassified
Jul 14, 2026
High7.1Red Hat

High [CVE-2026-15768] Insufficient policy enforcement in HTML-in-Canvas

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N). Weakness: CWE-346.

CVE-2026-15768
Unclassified
Jul 14, 2026
High7.4Red Hat

High [CVE-2026-15766] Uninitialized Use in Skia

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) An uninitialized use flaw was found in the Skia component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-824.

CVE-2026-15766
Unclassified
Jul 14, 2026
High7.5Vendor: CriticalRed Hat

High [CVE-2026-15764] Use after free in Ozone

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) An use after free flaw was found in the Ozone component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Critical — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15764
Unclassified
Jul 14, 2026