Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5201 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.7Linux

Low [CVE-2026-28387] Arbitrary code execution due to use-after-free in DANE TLSA authentication

Arbitrary code execution due to use-after-free in DANE TLSA authentication. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1341. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28387
Unclassified
Apr 7, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-35030] Authentication bypass and privilege escalation via OIDC userinfo cache key collision

Authentication bypass and privilege escalation via OIDC userinfo cache key collision. Red Hat rates this important (CVSS 9.1). Weakness: CWE-222. Affected package(s): ansible-automation-platform, rhoai/odh-llama-stack-core-rhel9:1781826406, rhoai/odh-llama-stack-core-rhel9:1782310008. Resolved in Red Hat advisory RHSA-2026:28960 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.

CVE-2026-35030
Unclassified
Apr 6, 2026
High7.5Linux

High [CVE-2026-35172] Information disclosure via stale references after content deletion

Information disclosure via stale references after content deletion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524. Affected package(s): openshift4/ose-operator-lifecycle-manager:1781122773, openshift4/ose-operator-lifecycle-manager-rhel9:1779915499, openshift4/ose-operator-lifecycle-manager:1781123052, openshift4/ose-operator-lifecycle-manager:1781833795, openshift4/ose-operator-lifecycle-manager-rhel9:1780957268. Resolved in Red Hat advisory RHSA-2026:28893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; and 2 more.

CVE-2026-35172
Unclassified
Apr 6, 2026
High8.8Linux

High [CVE-2026-35029] Remote code execution and privilege escalation via unrestricted proxy configuration endpoint

Remote code execution and privilege escalation via unrestricted proxy configuration endpoint. Red Hat rates this important (CVSS 8.8). Weakness: CWE-425. Affected package(s): ansible-automation-platform, rhoai/odh-llama-stack-core-rhel9:1781826406, rhoai/odh-llama-stack-core-rhel9:1782310008. Resolved in Red Hat advisory RHSA-2026:28960 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.

CVE-2026-35029
Unclassified
Apr 6, 2026
High7.5Linux

High [CVE-2026-34986] Denial of Service via crafted JSON Web Encryption (JWE) object

Denial of Service via crafted JSON Web Encryption (JWE) object. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131. Affected package(s): odf4/mcg-core-rhel9:1776403991, openshift-service-mesh/pilot-rhel8:1777319850, openshift-service-mesh/istio-cni-rhel8:1777374598, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-engine/assisted-installer-agent-rhel9:1776351169. Resolved in Red Hat advisory RHSA-2026:25194 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 77 more.

CVE-2026-34986
Red Hat Enterprise LinuxLinux Kernel
Apr 6, 2026
High8.8Linux

High [CVE-2026-34589] Memory corruption leading to arbitrary code execution or denial of service

Memory corruption leading to arbitrary code execution or denial of service. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34589
Unclassified
Apr 6, 2026
High8.8Linux

High [CVE-2026-34588] Arbitrary code execution and information disclosure via crafted EXR file

Arbitrary code execution and information disclosure via crafted EXR file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected package(s): openexr, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-cuda-rhel9:1782352847. Resolved in Red Hat advisory RHSA-2026:15888 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; and 2 more.

CVE-2026-34588
Red Hat Enterprise Linux
Apr 6, 2026
High8.1Linux

High [CVE-2026-34444] Arbitrary Code Execution due to inconsistent attribute filtering

Arbitrary Code Execution due to inconsistent attribute filtering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-914. Affected package(s): satellite/foreman-mcp-server-rhel9:1780492008. Resolved in Red Hat advisory RHSA-2026:22993 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Satellite 6.18.

CVE-2026-34444
Unclassified
Apr 6, 2026
High7.1Linux

High [CVE-2026-34379] Denial of Service due to misaligned memory write during EXR file decoding

Denial of Service due to misaligned memory write during EXR file decoding. Red Hat rates this important (CVSS 7.1). Weakness: CWE-475. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34379
Unclassified
Apr 6, 2026
High8.2Linux

High [CVE-2026-34982] arbitrary command execution via modeline sandbox bypass

arbitrary command execution via modeline sandbox bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-78. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, vim, rhui5/haproxy-rhel9:1779798164, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 13 more.

CVE-2026-34982
Red Hat Enterprise Linux
Apr 6, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-31408] Fix use-after-free in sco_recv_frame() due to missing sock_hold

Fix use-after-free in sco_recv_frame() due to missing sock_hold. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:19569 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-31408
Unclassified
Apr 6, 2026
Medium4.1Linux

Medium [CVE-2026-35177] Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass

Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-22. Affected package(s): vim, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, rhui5/rhua-rhel9:1781525739, insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35177
Unclassified
Apr 6, 2026
Medium4.6Linux

Medium [CVE-2026-35166] Information disclosure and content manipulation via improper markdown link escaping

Information disclosure and content manipulation via improper markdown link escaping. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79. Affected package(s): hugo-main. Resolved in Red Hat advisory RHSA-2026:7848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35166
Unclassified
Apr 6, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-34756] Denial of Service via excessively large 'n' parameter in OpenAI-compatible API

Denial of Service via excessively large 'n' parameter in OpenAI-compatible API. Red Hat rates this important (CVSS 6.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-34756
Red Hat Enterprise Linux
Apr 6, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-34755] Denial of Service due to excessive video frame processing

Denial of Service due to excessive video frame processing. Red Hat rates this important (CVSS 6.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-34755
Red Hat Enterprise Linux
Apr 6, 2026
Medium5.0Linux

Medium [CVE-2026-5704] Tar: tar: hidden file injection via crafted archives

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-434. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-5704
Red Hat Enterprise Linux
Apr 6, 2026
Medium6.7Vendor: HighLinux

Medium [CVE-2026-4878] Privilege escalation via TOCTOU race condition in cap_set_file()

Privilege escalation via TOCTOU race condition in cap_set_file(). Red Hat rates this important (CVSS 6.7). Weakness: CWE-367. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, libcap, rhui5/haproxy-rhel9:1779798164, rhcos, libcap-main. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 38 more.

CVE-2026-4878
Red Hat Enterprise Linux
Apr 6, 2026
Medium6.5Linux

Medium [CVE-2026-5265] Heap Over-Read in ICMP Error Response Generation

Heap Over-Read in ICMP Error Response Generation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-5265
Unclassified
Apr 6, 2026
Low3.7Linux

Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim

Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37977
Unclassified
Apr 6, 2026
High8.0Linux

High [CVE-2026-34780] Context Isolation bypass via VideoFrame object transfer

Context Isolation bypass via VideoFrame object transfer. Red Hat rates this important (CVSS 8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34780
Unclassified
Apr 4, 2026