Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1183 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.1Docker Updated

High [CVE-2026-17106] The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process. Affected products named by the advisory: Docker Sandboxes; Docker Desktop; Docker Engine; Docker CLI; and 1 more. Affected products named by the advisory: Docker Compose.

CVE-2026-17106
Docker DesktopDocker Engine / MobyBuildKit / ComposeDocker CLI / Scout
Aug 18, 2026
High7.9Red Hat Updated

High [CVE-2026-54552] Incomplete privilege drop allows child processes to retain privileged group access.

Incomplete privilege drop allows child processes to retain privileged group access. Red Hat rates this important (CVSS 7.9). Weakness: CWE-273. Affected product named by the advisory: Red Hat OpenShift Virtualization 4.

CVE-2026-54552
Unclassified
Aug 18, 2026
High8.2Red Hat

High [CVE-2026-66783] arbitrary image override enables privileged code execution on every node

arbitrary image override enables privileged code execution on every node. Red Hat rates this important (CVSS 8.2). Weakness: CWE-20. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66783
Unclassified
Aug 18, 2026
High7.8Red Hat

High [CVE-2026-66782] broker API bearer token stored cleartext in CR spec

broker API bearer token stored cleartext in CR spec. Red Hat rates this important (CVSS 7.8). Weakness: CWE-312. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66782
Unclassified
Aug 18, 2026
High8.7Red Hat

High [CVE-2026-75924] Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval

Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval. Red Hat rates this important (CVSS 8.7). Weakness: CWE-269. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-75924
Unclassified
Aug 18, 2026
High7.7Red Hat

High [CVE-2026-71365] webhook status callback SSRF leaks the Git PAT

webhook status callback SSRF leaks the Git PAT. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59153 with package automation-controller-0:4.7.16-1.el9ap, ansible-automation-platform-26/controller-rhel9:1787244009, automation-controller-0:4.6.32-1.el8ap, ansible-automation-platform-27/controller-rhel9:1787220257. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.

CVE-2026-71365
Unclassified
Aug 18, 2026
High8.8Red Hat

High [CVE-2026-66793] arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke

arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke. Red Hat rates this important (CVSS 8.8). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-governance-policy-addon-controller-rhel9:1787227696, rhacm2/acm-governance-policy-addon-controller-rhel9:1787080755, rhacm2/acm-governance-policy-addon-controller-rhel9:1787259078, rhacm2/acm-governance-policy-addon-controller-rhel9:1787080753. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66793
Unclassified
Aug 18, 2026
High8.8Red Hat Updated

High [CVE-2026-63639] Remote code execution via use-after-free in stream deserialization

Remote code execution via use-after-free in stream deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: valkey.

CVE-2026-63639
Red Hat Enterprise Linux
Aug 18, 2026
High7.5Red Hat Updated

High [CVE-2026-56684] Remote code execution via TLS pending-data processing use-after-free

Remote code execution via TLS pending-data processing use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: valkey.

CVE-2026-56684
Red Hat Enterprise Linux
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74988] Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154

Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130.

CVE-2026-74988
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74947] Privilege escalation due to invalid pointer in the Graphics component

Privilege escalation due to invalid pointer in the Graphics component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-74947
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74990] Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74990
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74938] Mitigation bypass in the JavaScript: GC component

Mitigation bypass in the JavaScript: GC component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807.

CVE-2026-74938
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74937] Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-74937
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-75874] Sandbox escape in the Remote Settings Client component

Sandbox escape in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653.

CVE-2026-75874
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74987] Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74987
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74948] Information disclosure in the Graphics component

Information disclosure in the Graphics component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-497. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74948
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74946] Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74946
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74949] Privilege escalation due to use-after-free in the Graphics: Canvas2D component

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74949
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74943] Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74943
Unclassified
Aug 18, 2026