Complete feed
Security advisories & CVEs
5203 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim
Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-34780] Context Isolation bypass via VideoFrame object transfer
Context Isolation bypass via VideoFrame object transfer. Red Hat rates this important (CVSS 8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.
High [CVE-2026-34774] Memory corruption and crash due to use-after-free in offscreen rendering
Memory corruption and crash due to use-after-free in offscreen rendering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.
High [CVE-2026-34771] Memory corruption or application crash via use-after-free in permission request handling
Memory corruption or application crash via use-after-free in permission request handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-364. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.
High [CVE-2026-34769] Arbitrary code execution and security bypass via undocumented command-line switches
Arbitrary code execution and security bypass via undocumented command-line switches. Red Hat rates this important (CVSS 7.7). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.
High [CVE-2026-0545] Unauthenticated remote code execution via unprotected job endpoints
Unauthenticated remote code execution via unprotected job endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-35535] Privilege escalation due to failure in privilege drop calls
Privilege escalation due to failure in privilege drop calls. Red Hat rates this important (CVSS 7.4). Weakness: CWE-272. Affected package(s): rhcos, sudo, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 18 more.
High [CVE-2026-23455] check for zero length in DecodeQ931()
check for zero length in DecodeQ931(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-31402] fix heap overflow in NFSv4.0 LOCK replay cache
fix heap overflow in NFSv4.0 LOCK replay cache. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION); Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION); Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux for Real Time (v. 7 ELS); and 60 more.
Medium [CVE-2026-34933] Denial of Service via D-Bus method call
Denial of Service via D-Bus method call. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected package(s): avahi-main. Resolved in Red Hat advisory RHSA-2026:11316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27456] TOCTOU in the mount program when setting up loop devices
TOCTOU in the mount program when setting up loop devices. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-367. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34980] Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-78. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34979] Denial of Service via heap-based buffer overflow in job attribute processing
Denial of Service via heap-based buffer overflow in job attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34978] Denial of Service via path traversal in RSS notifier
Denial of Service via path traversal in RSS notifier. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34990] Privilege escalation via arbitrary file overwrite due to coerced authentication
Privilege escalation via arbitrary file overwrite due to coerced authentication. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-73. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27447] Authorization bypass via case-insensitive username comparison
Authorization bypass via case-insensitive username comparison. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-178. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-35536] Cookie attribute injection due to improper handling of cookie arguments
Cookie attribute injection due to improper handling of cookie arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected package(s): python-tornado. Resolved in Red Hat advisory RHSA-2026:24342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-34742] Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access
Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access. Red Hat rates this important (CVSS 8). Weakness: CWE-1188. Affected package(s): devspaces/udi-rhel9:1779829736. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; OpenShift Serverless.
High [CVE-2026-34601] XML structure injection via CDATA terminator
XML structure injection via CDATA terminator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-34827] Denial of Service via crafted multipart/form-data requests
Denial of Service via crafted multipart/form-data requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.