Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

432 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-28498] Authentication bypass via forged OpenID Connect ID Tokens

Authentication bypass via forged OpenID Connect ID Tokens. Red Hat rates this important (CVSS 9.1). Weakness: CWE-325. Affected package(s): ansible-automation-platform, quay/quay-rhel9:1775069491, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1775169226, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; and 2 more.

CVE-2026-28498
Unclassified
Mar 16, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-27962] Authentication bypass due to JWK Header Injection vulnerability

Authentication bypass due to JWK Header Injection vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-347. Affected package(s): quay/quay-rhel9:1779204086, quay/quay-rhel8:1773971077, quay/quay-rhel8:1775512163, quay/quay-rhel8:1780891395. Resolved in Red Hat advisory RHSA-2026:7314 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.14; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.

CVE-2026-27962
Unclassified
Mar 16, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-31892] Security bypass allows privilege escalation via podSpecPatch field

Security bypass allows privilege escalation via podSpecPatch field. Red Hat rates this important (CVSS 9.9). Weakness: CWE-807. Affected package(s): rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9:1776740351, rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9:1776740640, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1776740726, rhoai/odh-data-science-pipelines-argo-argoexec-rhel9:1776740558, rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9:1776740366, rhoai/odh-ml-pipelines-driver-rhel9:1776740379. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.

CVE-2026-31892
Unclassified
Mar 11, 2026
Critical9.6Red Hat

Critical [CVE-2026-3913] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this critical (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3913
Unclassified
Mar 10, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-29186] TechDocs Mkdocs configuration key enables arbitrary code execution

TechDocs Mkdocs configuration key enables arbitrary code execution. Red Hat rates this important (CVSS 9.1). Weakness: CWE-791. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.

CVE-2026-29186
Unclassified
Mar 7, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-28802] Signature verification bypass via malicious JWT allows unauthorized access

Signature verification bypass via malicious JWT allows unauthorized access. Red Hat rates this important (CVSS 9.1). Weakness: CWE-347. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1773771962, quay/quay-rhel9:1779204086, quay/quay-rhel8:1773971077, quay/quay-rhel8:1773936323, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; and 3 more.

CVE-2026-28802
Unclassified
Mar 6, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-29068] Denial of Service via malformed RTP payload processing

Denial of Service via malformed RTP payload processing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-29068
Unclassified
Mar 6, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-27446] org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication

org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication. Red Hat rates this important (CVSS 9.1). Weakness: CWE-306. Affected package(s): eap8-activemq-artemis, artemis-server. Resolved in Red Hat advisory RHSA-2026:3955 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of OptaPlanner 8; Red Hat Fuse 7; and 3 more.

CVE-2026-27446
Unclassified
Mar 4, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-27606] Remote Code Execution via Path Traversal Vulnerability

Remote Code Execution via Path Traversal Vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-22. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, automation-gateway, ansible-automation-platform, devspaces/traefik-rhel9:1776718585, automation-platform-ui, quay/quay-rhel8:1773971077. Resolved in Red Hat advisory RHSA-2026:5649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Developer Hub 1.8; and 10 more.

CVE-2026-27606
Unclassified
Feb 25, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-24834] Arbitrary code execution in guest virtual machine via file system modification

Arbitrary code execution in guest virtual machine via file system modification. Red Hat rates this important (CVSS 9.3). Weakness: CWE-281. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-24834
Unclassified
Feb 19, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-25940] PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children)

PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children). Red Hat rates this important (CVSS 9.6). Weakness: CWE-116. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25940
Unclassified
Feb 19, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-25755] PDF object injection via unsanitized input in addJS method

PDF object injection via unsanitized input in addJS method. Red Hat rates this important (CVSS 9.6). Weakness: CWE-94. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25755
Unclassified
Feb 19, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-1615] Arbitrary Code Execution via unsafe JSON Path expression evaluation

Arbitrary Code Execution via unsafe JSON Path expression evaluation. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected package(s): ansible-automation-platform, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.9; OpenShift Pipelines; and 2 more.

CVE-2026-1615
Unclassified
Feb 9, 2026
Critical9.4Red Hat

Critical [CVE-2026-1709] Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication

Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-322. Affected package(s): keylime. Resolved in Red Hat advisory RHSA-2026:2225 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.

CVE-2026-1709
Unclassified
Feb 6, 2026
Critical9.3Red Hat

Critical [CVE-2026-25521] Locutus is vulnerable to Prototype Pollution

Locutus is vulnerable to Prototype Pollution. Red Hat rates this critical (CVSS 9.3). Weakness: CWE-915. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-25521
Unclassified
Feb 4, 2026
Critical9.8Red Hat

Critical [CVE-2026-22778] Remote code execution via invalid image processing in the multimodal endpoint.

Remote code execution via invalid image processing in the multimodal endpoint.. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-209. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-rocm-rhel9:1772093237, rhoai/odh-vllm-cpu-rhel9:1772093436. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.

CVE-2026-22778
Unclassified
Feb 2, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2025-15467] Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. Affected package(s): service-interconnect/skupper-operator-bundle:1.8.8, devspaces/dashboard-rhel9:1770764461, devspaces/pluginregistry-rhel9:1770918006, service-interconnect/skupper-controller-podman-container-rhel9:1.8.8, rhui5/rhua-rhel9:1773670137, openssl. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; and 32 more.

CVE-2025-15467
Unclassified
Jan 27, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-24480] QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration

QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration. Red Hat rates this important (CVSS 9.9). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24480
Unclassified
Jan 27, 2026
Critical9.1Red Hat

Critical [CVE-2026-20912] Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure

Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-283. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-20912
Unclassified
Jan 22, 2026
Critical9.1Red Hat

Critical [CVE-2026-20897] Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)

Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR). Red Hat rates this critical (CVSS 9.1). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-20897
Unclassified
Jan 22, 2026