Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5203 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.7Linux

Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim

Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37977
Unclassified
Apr 6, 2026
High8.0Linux

High [CVE-2026-34780] Context Isolation bypass via VideoFrame object transfer

Context Isolation bypass via VideoFrame object transfer. Red Hat rates this important (CVSS 8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34780
Unclassified
Apr 4, 2026
High8.1Linux

High [CVE-2026-34774] Memory corruption and crash due to use-after-free in offscreen rendering

Memory corruption and crash due to use-after-free in offscreen rendering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34774
Unclassified
Apr 3, 2026
High7.5Linux

High [CVE-2026-34771] Memory corruption or application crash via use-after-free in permission request handling

Memory corruption or application crash via use-after-free in permission request handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-364. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34771
Unclassified
Apr 3, 2026
High7.7Linux

High [CVE-2026-34769] Arbitrary code execution and security bypass via undocumented command-line switches

Arbitrary code execution and security bypass via undocumented command-line switches. Red Hat rates this important (CVSS 7.7). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34769
Unclassified
Apr 3, 2026
High8.1Linux

High [CVE-2026-0545] Unauthenticated remote code execution via unprotected job endpoints

Unauthenticated remote code execution via unprotected job endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-0545
Unclassified
Apr 3, 2026
High7.4Linux

High [CVE-2026-35535] Privilege escalation due to failure in privilege drop calls

Privilege escalation due to failure in privilege drop calls. Red Hat rates this important (CVSS 7.4). Weakness: CWE-272. Affected package(s): rhcos, sudo, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 18 more.

CVE-2026-35535
Red Hat Enterprise Linux
Apr 3, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-23455] check for zero length in DecodeQ931()

check for zero length in DecodeQ931(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23455
Unclassified
Apr 3, 2026
High7.8Linux

High [CVE-2026-31402] fix heap overflow in NFSv4.0 LOCK replay cache

fix heap overflow in NFSv4.0 LOCK replay cache. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION); Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION); Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux for Real Time (v. 7 ELS); and 60 more.

CVE-2026-31402
Red Hat Enterprise Linux
Apr 3, 2026
Medium5.5Linux

Medium [CVE-2026-34933] Denial of Service via D-Bus method call

Denial of Service via D-Bus method call. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected package(s): avahi-main. Resolved in Red Hat advisory RHSA-2026:11316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34933
Unclassified
Apr 3, 2026
Medium4.7Linux

Medium [CVE-2026-27456] TOCTOU in the mount program when setting up loop devices

TOCTOU in the mount program when setting up loop devices. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-367. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27456
Unclassified
Apr 3, 2026
Medium6.4Linux

Medium [CVE-2026-34980] Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network

Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-78. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34980
Unclassified
Apr 3, 2026
Medium5.3Linux

Medium [CVE-2026-34979] Denial of Service via heap-based buffer overflow in job attribute processing

Denial of Service via heap-based buffer overflow in job attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34979
Unclassified
Apr 3, 2026
Medium6.5Linux

Medium [CVE-2026-34978] Denial of Service via path traversal in RSS notifier

Denial of Service via path traversal in RSS notifier. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34978
Unclassified
Apr 3, 2026
Medium5.2Linux

Medium [CVE-2026-34990] Privilege escalation via arbitrary file overwrite due to coerced authentication

Privilege escalation via arbitrary file overwrite due to coerced authentication. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-73. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34990
Unclassified
Apr 3, 2026
Medium6.4Linux

Medium [CVE-2026-27447] Authorization bypass via case-insensitive username comparison

Authorization bypass via case-insensitive username comparison. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-178. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27447
Unclassified
Apr 3, 2026
Medium5.4Linux

Medium [CVE-2026-35536] Cookie attribute injection due to improper handling of cookie arguments

Cookie attribute injection due to improper handling of cookie arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected package(s): python-tornado. Resolved in Red Hat advisory RHSA-2026:24342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-35536
Unclassified
Apr 3, 2026
High8.0Linux

High [CVE-2026-34742] Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access

Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access. Red Hat rates this important (CVSS 8). Weakness: CWE-1188. Affected package(s): devspaces/udi-rhel9:1779829736. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; OpenShift Serverless.

CVE-2026-34742
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-34601] XML structure injection via CDATA terminator

XML structure injection via CDATA terminator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34601
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-34827] Denial of Service via crafted multipart/form-data requests

Denial of Service via crafted multipart/form-data requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.

CVE-2026-34827
Unclassified
Apr 2, 2026