Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.9Red Hat

Medium [CVE-2026-53668] Cross-Site Scripting (XSS) via open redirects

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector. This issue has been fixed in version 7.13.0. In addition to the redirect itself, a crafted target URL can be used to achieve Cross-Site Scripting (XSS) against the vulnerable application, potentially exposing session data or allowing unauthorized actions in the context of the redirecting origin. Red Hat's CVSS score (6.9, AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N) matches the upstream/CVE.org self-assigned score exactly, so no Red Hat-specific re-scoring was applied. Red Hat severity: Moderate — CVSS 6.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N). Weakness: CWE-601. Affected products named by the advisory: Cryostat 4; Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; OpenShift Lightspeed; and 16 more.

CVE-2026-53668
Unclassified
Jul 27, 2026
Medium6.9Red Hat

Medium [CVE-2026-53667] Untrusted redirects due to missing protocol validation

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0. The RSCErrorHandler component, used in applications leveraging unstable React Server Components (RSC) Application Programming Interfaces (APIs), is missing crucial protocol validation. This vulnerability allows an attacker to redirect users to untrusted external websites. Such redirects can lead to information disclosure or facilitate phishing attacks, potentially exposing sensitive user data. Red Hat's CVSS score (6.9, AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N) matches the upstream/CVE.org self-assigned score exactly, so no Red Hat-specific re-scoring was applied. Red Hat severity: Moderate — CVSS 6.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N). Weakness: CWE-601. Affected products named by the advisory: Exploit Intelligence; Network Observability Operator; OpenShift Lightspeed; OpenShift Pipelines; and 8 more.

CVE-2026-53667
Unclassified
Jul 27, 2026
Medium6.1Red Hat

Medium [CVE-2026-53666] Information disclosure via client-side constructor execution

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0. This execution could lead to an outbound network request, potentially resulting in limited information disclosure or unintended network activity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-502. Affected products named by the advisory: Cryostat 4; Exploit Intelligence; Gatekeeper 3; Migration Toolkit for Applications 8; and 41 more. Affected products named by the advisory: Migration Toolkit for Containers; Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Network Observability Operator; and 37 more.

CVE-2026-53666
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.5Red Hat

Medium [CVE-2026-66757] signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on RLE SGI images

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-66757
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.3Red Hat

Medium [CVE-2026-64643] Information disclosure via Server Action ID exposure

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). By itself, this disclosure is typically a recon/enumeration primitive; however, it can increase risk when combined with other weaknesses. This issue has been fixed in versions 15.5.21 and 16.2.11. A flaw was found in Next.js. This bypasses authentication on pages where these endpoints are used, leading to information disclosure. This Moderate information disclosure vulnerability in Next.js applications allows unauthenticated users to obtain Server Action IDs from publicly served client artifacts. While primarily a reconnaissance primitive, this exposure could increase overall risk when chained with other weaknesses. Red Hat products and services that incorporate Next.js, such as Red Hat AMQ, Red Hat Enterprise Linux AI, and cloud.redhat.com offerings, are affected. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201.

CVE-2026-64643
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.0Red Hat

Medium [CVE-2026-17574] Denial of Service via crafted HDF5 file processing

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read. A flaw was found in HDF5. A local user can exploit this vulnerability by processing a specially crafted HDF5 file. This issue affects Red Hat products that utilize HDF5 for data handling, requiring user interaction to process the malicious file. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-17574
Unclassified
Jul 27, 2026
Medium5.0Red Hat

Medium [CVE-2026-17573] HDF5 library: Denial of Service via crafted HDF5 file processing

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free. This could cause the application to unexpectedly terminate, leading to a denial of service. This Moderate severity flaw in the HDF5 library can lead to a denial of service. It requires a local attacker to trick a user into processing a specially crafted HDF5 file with the `h5repack` utility, which could cause the application to crash due to a double free vulnerability. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-763. Affected Red Hat products: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-17573
Unclassified
Jul 27, 2026
Medium5.5Red Hat

Medium [CVE-2026-17572] Denial of Service via crafted file requiring user interaction

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum. A flaw was found in HDF5, a data management library. The malformed file can trigger out-of-bounds memory operations, leading to application crashes or instability. This Moderate impact vulnerability in HDF5 requires user interaction to process a specially crafted HDF5 file, limiting the attack vector to local scenarios. Successful exploitation can lead to a denial of service. The HDF5 library is used in Red Hat Enterprise Linux AI, Red Hat AI Inference Server, and Red Hat OpenShift AI. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-17572
Unclassified
Jul 27, 2026
Medium4.4Red Hat

Medium [CVE-2026-47078] Arbitrary file write via relative path traversal in zip module

Arbitrary file write via relative path traversal in zip module. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22.

CVE-2026-47078
Unclassified
Jul 27, 2026
Medium5.6Red Hat

Medium [CVE-2026-15003] Heap-buffer-overflow in linker leads to information disclosure and denial of service

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing. This vulnerability is rated as High. A heap-buffer-overflow in the GNU Binutils linker (`ld`) can lead to information disclosure and denial of service when processing specially crafted 32-bit XCOFF object files. This occurs because the linker uses an unvalidated field from untrusted input as an array index, potentially exposing heap metadata or causing a crash during the linking process. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:47171.

CVE-2026-15003
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.9Red Hat

Medium [CVE-2026-66053] Apache Thrift Python bindings: Information disclosure due to improper certificate validation

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603 This vulnerability, stemming from improper validation of certificates with host mismatch, could allow a remote attacker to intercept and access sensitive information. The issue occurs when the Python client fails to adequately verify the server's certificate against its hostname, potentially enabling a man-in-the-middle (MITM) attack and leading to information disclosure. While Red Hat Enterprise Linux AI is not affected, OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are impacted where these bindings are used in network communication. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:49837.

CVE-2026-66053
Unclassified
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-58023] Information disclosure and denial of service due to out-of-bounds read

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This out-of-bounds read vulnerability allows an attacker to potentially access sensitive information or cause a denial of service. The vulnerability occurs when the software attempts to read data beyond the allocated memory buffer. Red Hat products such as OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are affected where they utilize vulnerable versions of Apache Thrift. Red Hat Enterprise Linux AI is not affected as the vulnerable code is not present. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-58023
Unclassified
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-55970] Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This buffer over-read vulnerability allows a remote attacker to read beyond the intended memory boundaries. This could lead to the disclosure of sensitive information or cause the application to become unavailable. Red Hat products utilizing affected versions of Apache Thrift, such as Red Hat Enterprise Linux AI, OpenShift Container Platform, and Red Hat OpenShift AI, may be susceptible if processing untrusted data with Thrift client applications. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Confidential Compute Attestation; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Update Service. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-55970
Unclassified
Jul 27, 2026
Medium5.9Red Hat

Medium [CVE-2026-48145] Information disclosure due to improper certificate validation

Information disclosure due to improper certificate validation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-297.

CVE-2026-48145
Unclassified
Jul 27, 2026
Medium6.8Red Hat

Medium [CVE-2026-16554] Remote code execution due to integer overflow via crafted JSON

cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. The escape_characters counter, a 32-bit size_t, can wrap around when processing strings containing approximately 858,993,460 or more control characters, causing the output buffer to be allocated based on an underestimated length. When cJSON_PrintBuffered() is used with a pre-allocated buffer, the subsequent write loop overflows the heap allocation. An attacker supplying a crafted JSON string to an application using cJSON on a 32-bit platform can cause a heap buffer overflow, potentially leading to remote code execution, information disclosure, or denial of service. Because project creator contact attempts were unsuccessful, the vulnerability has only been confirmed in version 1.7.19 but may also affect other versions. This issue does not affect the versions of cJSON, or of components that vendor/bundle it (such as rpm-ostree), as shipped with Red Hat Enterprise Linux, Red Hat Satellite, or OpenShift Container Platform.

CVE-2026-16554
Unclassified
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-64535] Fix potential UAF when ddgst mismatch

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which performs percpu_ref_put() on the submission queue — but does NOT mark the command as completed. It does not set cqe->status, does not modify rbytes_done, and does not clear any flag. When the subsequent fatal error triggers queue teardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands, checks nvmet_tcp_need_data_in() for each one, and finds that the already-uninited command still appears to need data (because rbytes_done status == 0). It therefore calls nvmet_req_uninit() a second time on the same command — a double percpu_ref_put against a single percpu_ref_get. A use-after-free flaw was found in the Linux kernel's NVMe-over-Fabrics TCP target (nvmet-tcp) driver. This use-after-free and reference-count underflow can crash the kernel (denial of service) when a remote NVMe/TCP initiator triggers a digest mismatch against a host configured as an NVMe/TCP target.

CVE-2026-64535
Linux Kernel
Jul 27, 2026
Medium5.3Red Hat

Medium [CVE-2026-17501] Denial of Service due to resource allocation manipulation in JSON-Schema-to-GBNF Conversion

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance. This flaw allows for the manipulation of resource allocation, which can lead to a denial of service (DoS) by exhausting available system resources. Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the affected packages, refer to the linked references. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-1050.

CVE-2026-17501
Unclassified
Jul 27, 2026
Medium5.3Red Hat

Medium [CVE-2026-64538] Fix null-ptr-deref in fib6_nh_mtu_change

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). fib6_nh_mtu_change() re-fetches idev via __in6_dev_get(arg->dev) and dereferences idev->cnf.mtu6 without a NULL check. addrconf_ifdown() clears dev->ip6_ptr with RCU_INIT_POINTER() after rt6_disable_ip() has released tb6_lock, so the RA-driven MTU walk can observe a NULL idev and oops. The caller rt6_mtu_change_route() guards its own __in6_dev_get(), but this re-fetch is unguarded; nexthop-backed routes survive addrconf_ifdown()'s flush, so the walk still reaches it after ip6_ptr is nulled. Return 0 when idev is NULL, matching rt6_mtu_change_route() and the fib6_mtu() fix in commit 5ad509c1fdad ("ipv6: Fix null-ptr-deref in fib6_mtu()."). Oops: general protection fault,... KASAN: null-ptr-deref in range [0x00000000000002a8-0x00000000000002af] RIP: 0010:fib6_nh_mtu_change+0x203/0x990 rt6_mtu_change_route+0x141/0x1d0 __fib6_clean_all+0xd0/0x160 rt6_mtu_change+0xb4/0x100 ndisc_router_discovery+0x24b5/0x2cb0 icmpv6_rcv+0x12e9/0x1710 ipv6_rcv+0x39b/0x410 A flaw was found in the Linux kernel's IPv6 networking component. A null pointer dereference vulnerability exists in the `fib6_nh_mtu_change()` function. An attacker could potentially trigger this condition, leading to a kernel crash and a Denial of Service (DoS).

CVE-2026-64538
Red Hat Enterprise LinuxLinux Kernel
Jul 27, 2026
MediumRed Hat

Medium [CVE-2026-64532] bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}

bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}. Red Hat rates this moderate. Weakness: CWE-120.

CVE-2026-64532
Unclassified
Jul 27, 2026
Medium5.5Red Hat

Medium [CVE-2026-64553] fix info leak in PSAMPLE_ATTR_DATA

fix info leak in PSAMPLE_ATTR_DATA. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-212.

CVE-2026-64553
Unclassified
Jul 27, 2026