Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.7Red Hat

High [CVE-2026-17527] cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role. This flaw is confirmed upstream in kubevirt/containerized-data-importer and affects all downstream consumers using CDI's default aggregated RBAC roles, including OpenShift Virtualization. It is distinct from the SSP operator's "golden images" pattern, which deliberately and correctly scopes an equivalent permission via a namespace-scoped Role/RoleBinding. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-639.

CVE-2026-17527
Unclassified
Jul 27, 2026
High7.4Red Hat

High [CVE-2026-15928] Cross-Site Scripting in error page component

Cross-Site Scripting in error page component. Red Hat rates this important (CVSS 7.4). Weakness: CWE-79.

CVE-2026-15928
Unclassified
Jul 27, 2026
High8.1Red Hat

High [CVE-2026-51300] Application crash and information leakage due to use-after-free

A flaw was found in SQLite. This use-after-free vulnerability exists in the expression parsing and memory management logic. A remote attacker can exploit this by crafting malicious SQL queries, which leads to invalid memory access. This can result in an application crash and the leakage of sensitive memory information. Red Hat Product Security has evaluated CVE-2026-51300, which claims a Use-After-Free vulnerability in SQLite. After conducting independent analysis of the affected SQLite versions, Red Hat has determined that this vulnerability does not affect our products. SQLite upstream have confirmed this CVE as fictitious ( ). This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-51300
Unclassified
Jul 27, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-51298] Denial of Service via use-after-free in JSON extraction

A flaw was found in SQLite. A remote attacker could exploit a use-after-free vulnerability in the JSON extraction function. This occurs when the program attempts to access memory after it has been freed, specifically within the `JsonParse` object. Successful exploitation of this vulnerability can lead to a service crash and a denial of service (DoS) for affected systems. This Moderate flaw in SQLite's JSON extraction function can lead to a denial of service. Applications that process untrusted JSON input using SQLite in Red Hat products are susceptible to a service crash due to a use-after-free vulnerability. This could impact the availability of services relying on SQLite for JSON data handling. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:45779. Affected products named by the advisory: Red Hat package: rust.

CVE-2026-51298
Red Hat Enterprise Linux
Jul 27, 2026
High7.6Red Hat

High [CVE-2026-51302] Arbitrary code execution via malicious SQL statement

A flaw was found in SQLite. A use-after-free vulnerability in the expression evaluation logic, specifically within the sqlite3ReleaseTempReg and exprComputeOperands functions, allows a remote attacker to exploit the system. By supplying a malicious SQL statement, an attacker can cause a denial of service, leak sensitive information, or potentially execute arbitrary code. Red Hat Product Security has evaluated CVE-2026-51302, which claims a Use-After-Free vulnerability in SQLite. After conducting independent analysis of the affected SQLite versions, Red Hat has determined that this vulnerability does not affect our products. SQLite upstream have confirmed this CVE as fictitious ( ). This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:45779.

CVE-2026-51302
Unclassified
Jul 27, 2026
High8.2Red Hat

High [CVE-2026-51296] Use-after-free vulnerability leads to denial of service and information disclosure

A flaw was found in SQLite. A use-after-free vulnerability in the SQLite JSON module's jsonRemoveFunc allows a remote attacker to cause a denial of service by crashing the service. This vulnerability can also lead to the disclosure of sensitive heap memory information. Red Hat Product Security has evaluated CVE-2026-51296, which claims a Use-After-Free vulnerability in SQLite. After conducting independent analysis of the affected SQLite versions, Red Hat has determined that this vulnerability does not affect our products. SQLite upstream have confirmed this CVE as fictitious ( ). This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-51296
Unclassified
Jul 27, 2026
High7.6Red Hat

High [CVE-2026-51297] Arbitrary code execution via use-after-free in JSON parsing

A flaw was found in sqlite. This use-after-free vulnerability in the JSON parsing logic allows remote attackers to craft malicious JSON payloads. This can trigger memory deallocation followed by illegal memory access, potentially leading to arbitrary code execution, sensitive information leakage, or denial of service. Red Hat Product Security has evaluated CVE-2026-51297, which claims a Use-After-Free vulnerability in SQLite. After conducting independent analysis of the affected SQLite versions, Red Hat has determined that this vulnerability does not affect our products. SQLite upstream have confirmed this CVE as fictitious ( ). This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:45779.

CVE-2026-51297
Unclassified
Jul 27, 2026
High7.6Red Hat

High [CVE-2026-51303] Arbitrary code execution via specially crafted SQL queries

A flaw was found in SQLite. A remote attacker can exploit a use-after-free vulnerability in the core parsing component by sending specially crafted SQL queries. This can lead to an application crash, sensitive information disclosure, and potentially allow the attacker to execute arbitrary code on the affected system. Red Hat Product Security has evaluated CVE-2026-51303, which claims a Use-After-Free vulnerability in SQLite. After conducting independent analysis of the affected SQLite versions, Red Hat has determined that this vulnerability does not affect our products. SQLite upstream have confirmed this CVE as fictitious ( ). This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-51303
Unclassified
Jul 27, 2026
High7.6Red Hat

High [CVE-2026-51304] Arbitrary code execution via malicious SQL statement

A flaw was found in sqlite. A remote attacker can exploit a use-after-free vulnerability in the ORDER BY clause parsing routine by crafting a malicious SQL statement. This can lead to an application crash, sensitive information disclosure, and in some cases, arbitrary code execution, allowing the attacker to run their own commands on the affected system. Red Hat Product Security has evaluated CVE-2026-51304, which claims a Use-After-Free vulnerability in SQLite. After conducting independent analysis of the affected SQLite versions, Red Hat has determined that this vulnerability does not affect our products. SQLite upstream have confirmed this CVE as fictitious ( ). This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:45779.

CVE-2026-51304
Unclassified
Jul 27, 2026
High7.0Red Hat

High [CVE-2026-64534] check INIT_FAILED before nvmet_req_uninit in digest error path

check INIT_FAILED before nvmet_req_uninit in digest error path. Red Hat rates this important (CVSS 7). Weakness: CWE-911.

CVE-2026-64534
Unclassified
Jul 27, 2026
High7.8Red Hat

High [CVE-2026-64531] reject oversized nested action attrs

reject oversized nested action attrs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:53330 with package kernel-0:6.12.0-211.46.1.el10_2, kernel-rt-0:5.14.0-284.186.1.rt14.471.el9_2, kernel-0:5.14.0-427.143.1.el9_4, kernel-0:5.14.0-284.186.1.el9_2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-64531
Unclassified
Jul 27, 2026
High7.3Red Hat

High [CVE-2026-51235] Buffer Overflow vulnerability in image processing

Buffer Overflow vulnerability in image processing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:51105 with package LibRaw-0:0.21.1-2.el9_8.1. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-51235
Unclassified
Jul 27, 2026
High7.0Red Hat

High [CVE-2026-64552] fix len check in receive_big

fix len check in receive_big(). Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64552
Unclassified
Jul 27, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64551] validate STALE_COOKIE cause length before reading staleness

validate STALE_COOKIE cause length before reading staleness. Red Hat rates this moderate (CVSS 7).

CVE-2026-64551
Unclassified
Jul 27, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64554] fix stale prevhdr pointer in br_ip6_fragment

fix stale prevhdr pointer in br_ip6_fragment(). Red Hat rates this moderate (CVSS 7).

CVE-2026-64554
Unclassified
Jul 27, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64543] fix use-after-free of the discoverer in tipc_disc_rcv

fix use-after-free of the discoverer in tipc_disc_rcv(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64543
Unclassified
Jul 27, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64539] Fix stack OOB write when prepending the Flags AD

Fix stack OOB write when prepending the Flags AD. Red Hat rates this moderate (CVSS 7).

CVE-2026-64539
Unclassified
Jul 27, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64548] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data

bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.

CVE-2026-64548
Unclassified
Jul 27, 2026
Medium5.4Red Hat

Medium [CVE-2026-53669] Open Redirect vulnerability via backslashes in navigation components

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0. A remote attacker could exploit this vulnerability by crafting a malicious link that uses backslashes within the or useNavigate components. This could lead to an Open Redirect, allowing the attacker to redirect users to arbitrary external websites, potentially for phishing or other malicious purposes. This could facilitate phishing attacks against users. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-601. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Exploit Intelligence; Gatekeeper 3; and 41 more. Affected products named by the advisory: Migration Toolkit for Applications 8; Migration Toolkit for Containers; Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; and 37 more.

CVE-2026-53669
Red Hat Enterprise Linux
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-55685] @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue has been fixed in version 7.18.0. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application. Repeated, targeted requests to this endpoint place heavy load on the server and can degrade or deny service for other users. Applications using Declarative Mode () or Data Mode (createBrowserRouter/) do not run this server-side code path and are not affected. This mirrors the same re-scoring applied to the predecessor flaw, CVE-2026-42342, for the same endpoint family. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat OpenShift AI 3.4; Exploit Intelligence; Network Observability Operator; OpenShift Lightspeed; and 13 more.

CVE-2026-55685
Red Hat Enterprise Linux
Jul 27, 2026