Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.8Red Hat

Medium [CVE-2026-46678] Server-Side Request Forgery (SSRF) bypass exposes cloud credentials.

Server-Side Request Forgery (SSRF) bypass exposes cloud credentials. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-918.

CVE-2026-46678
Unclassified
Jul 29, 2026
Medium6.5Red Hat

Medium [CVE-2026-65975] Remote clients can execute server tools with forged arguments due to improper message sanitization.

Remote clients can execute server tools with forged arguments due to improper message sanitization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected product named by the advisory: Lightspeed Core.

CVE-2026-65975
Unclassified
Jul 29, 2026
Medium5.9Red Hat

Medium [CVE-2026-13346] Arbitrary file installation via malicious package indexes

Arbitrary file installation via malicious package indexes. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:48788 with package python-pip-main-26.2-0.1.hum1.

CVE-2026-13346
Unclassified
Jul 29, 2026
Medium4.3Red Hat

Medium [CVE-2026-62995] JWT Malleability via Non-Standard Padding

JWT Malleability via Non-Standard Padding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1286. Red Hat lists fixing advisory RHSA-2026:48758 with package jaeger-main-2.20.0-0.8.hum1.

CVE-2026-62995
Unclassified
Jul 29, 2026
Medium4.8Red Hat

Medium [CVE-2026-16729] Cookie attribute injection allows bypassing security protections

Cookie attribute injection allows bypassing security protections. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-140. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-16729
Unclassified
Jul 29, 2026
Medium4.7Red Hat

Medium [CVE-2026-52791] Privilege Escalation Vulnerability via SUID/SGID Bit Preservation

Privilege Escalation Vulnerability via SUID/SGID Bit Preservation. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-281.

CVE-2026-52791
Unclassified
Jul 29, 2026
Medium5.9Red Hat

Medium [CVE-2026-67216] Denial of Service due to inefficient JSON object comparison

Denial of Service due to inefficient JSON object comparison. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770.

CVE-2026-67216
Unclassified
Jul 29, 2026
Medium4.4Red Hat

Medium [CVE-2026-50642] Terminal escape injection allows command execution

Terminal escape injection allows command execution. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-94.

CVE-2026-50642
Unclassified
Jul 29, 2026
Medium5.6Red Hat

Medium [CVE-2026-56390] Arbitrary file overwrite via grammar-defined output paths

Arbitrary file overwrite via grammar-defined output paths. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-22.

CVE-2026-56390
Unclassified
Jul 29, 2026
Medium5.5Red Hat

Medium [CVE-2026-56389] Arbitrary Code Execution via malicious grammar file

Arbitrary Code Execution via malicious grammar file. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: bison.

CVE-2026-56389
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.5Red Hat

Medium [CVE-2026-18201] Generic identity-provider creation can bind brokers to organizations without manage-organizations

Generic identity-provider creation can bind brokers to organizations without manage-organizations. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18201
Unclassified
Jul 29, 2026
Medium6.5Red Hat

Medium [CVE-2026-18207] CVE-2026-18207

CVE-2026-18207. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-285. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-18207
Unclassified
Jul 29, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-18107] container escape via rseq critical section hijack during checkpoint/restore

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities. Red Hat severity: Moderate — CVSS 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-18107
Red Hat Enterprise Linux
Jul 28, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-71190] Unauthenticated denial of service via catastrophic backtracking in Accept header parser

Unauthenticated denial of service via catastrophic backtracking in Accept header parser. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333.

CVE-2026-71190
Unclassified
Jul 28, 2026
High8.2Red Hat

High [CVE-2026-71191] S3API presigned URL unsigned header authorization bypass

S3API presigned URL unsigned header authorization bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863.

CVE-2026-71191
Unclassified
Jul 28, 2026
High8.1Red Hat

High [CVE-2026-66713] Remote code execution via deserialization of untrusted data in Tribes clustering

Remote code execution via deserialization of untrusted data in Tribes clustering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502.

CVE-2026-66713
Unclassified
Jul 28, 2026
High8.5Red Hat

High [CVE-2026-49332] underscore header smuggling enables identity impersonation on WSGI/PHP upstreams

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-436. Affected Red Hat products: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22. Red Hat fixing advisory: RHSA-2026:54206, RHSA-2026:54188, RHSA-2026:50681, RHSA-2026:56912, RHSA-2026:50758, RHSA-2026:51013, RHSA-2026:51007, RHSA-2026:51022, RHSA-2026:51025, RHSA-2026:51038.

CVE-2026-49332
Unclassified
Jul 28, 2026
High7.5Red Hat

High [CVE-2026-65624] Denial of Service via HTTP/1.1 duplicate header names

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in a map (maps:size(Headers)). When a request contains multiple header lines with the same name, the values are concatenated into a single ever-growing binary stored under that one map key (", " for regular headers, "; " for cookies), so the map size stays at one and the max_headers cap (default 100) is never reached. Because no accumulator bounds the total number of header lines or the total byte size of the header block (only per-line max_header_name_length and max_header_value_length apply), an unauthenticated client can send an arbitrary number of header lines with the same name and grow the connection process's binary memory to arbitrary size within the request window. The impact per connection is bounded by request_timeout (default 5 seconds, not reset by header data), and by max_heap_size when set (the offending connection process is killed once its heap grows past the limit). When max_heap_size is left at the default (unset), sustained abuse can drive the Erlang VM into out-of-memory conditions. This issue affects cowboy from 2.0.0-pre.4 before 2.18.0.

CVE-2026-65624
Unclassified
Jul 28, 2026
High7.5Red Hat

High [CVE-2026-6949] TSIG packet with crafted name compression can crash DNS server

TSIG packet with crafted name compression can crash DNS server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-6949
Unclassified
Jul 28, 2026
High8.8Red Hat

High [CVE-2026-58222] Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes

Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes. Red Hat rates this important (CVSS 8.8). Weakness: CWE-90.

CVE-2026-58222
Unclassified
Jul 28, 2026