Complete feed
Security advisories & CVEs
5204 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-34827] Denial of Service via crafted multipart/form-data requests
Denial of Service via crafted multipart/form-data requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.
High [CVE-2026-34829] Denial of Service via unbounded multipart file upload
Denial of Service via unbounded multipart file upload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat 3scale API Management Platform 2.
High [CVE-2026-34785] Information disclosure via incorrect static file serving prefix check
Information disclosure via incorrect static file serving prefix check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-552. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-35385] Privilege escalation via scp legacy protocol when not preserving file mode
Privilege escalation via scp legacy protocol when not preserving file mode. Red Hat rates this important (CVSS 7.5). Weakness: CWE-281. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, openssh, rhcos, rhui5/rhua-rhel9:1779798222, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 22 more.
High [CVE-2026-32871] Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters
Authenticated Server-Side Request Forgery via path traversal in OpenAPI path parameters. Red Hat rates this important (CVSS 8.5). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Satellite 6.18.
High [CVE-2026-31937] Denial of Service via DCERPC buffering inefficiency
Denial of Service via DCERPC buffering inefficiency. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31935] Denial of Service via HTTP2 continuation frame flooding
Denial of Service via HTTP2 continuation frame flooding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31934] Denial of Service via quadratic complexity in URL search of MIME-encoded SMTP messages
Denial of Service via quadratic complexity in URL search of MIME-encoded SMTP messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31933] Denial of Service due to specially crafted network traffic
Denial of Service due to specially crafted network traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31932] Denial of Service due to inefficiency in KRB5 buffering
Denial of Service due to inefficiency in KRB5 buffering. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31931] Denial of Service via 'tls.alpn' rule keyword
Denial of Service via 'tls.alpn' rule keyword. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3872] Information disclosure due to redirect_uri validation bypass
Information disclosure due to redirect_uri validation bypass. Red Hat rates this important (CVSS 7.3). Weakness: CWE-601. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
High [CVE-2026-4282] Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw
Privilege escalation via forged authorization codes due to SingleUseObjectProvider isolation flaw. Red Hat rates this important (CVSS 7.4). Weakness: CWE-653. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
High [CVE-2026-4634] Denial of Service via excessive processing of OpenID Connect scope parameters
Denial of Service via excessive processing of OpenID Connect scope parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
High [CVE-2026-4636] UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
UMA policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.. Red Hat rates this important (CVSS 8.1). Weakness: CWE-551. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
Medium [CVE-2026-34743] Denial of Service via buffer overflow in index decoding
Denial of Service via buffer overflow in index decoding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-131. Affected package(s): xz-main. Resolved in Red Hat advisory RHSA-2026:7647 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-35414] Security bypass via mishandling of authorized_keys principals option
Security bypass via mishandling of authorized_keys principals option. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-168. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-4325] Replay of action tokens via improper handling of single-use entries
Replay of action tokens via improper handling of single-use entries. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-653. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-35388] Low integrity impact from unconfirmed proxy-mode multiplexing sessions
Low integrity impact from unconfirmed proxy-mode multiplexing sessions. Red Hat rates this low (CVSS 2.2). Weakness: CWE-306. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, discovery/discovery-ui-rhel9:1778156756, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-35387] Information disclosure due to unintended cryptographic algorithm usage
Information disclosure due to unintended cryptographic algorithm usage. Red Hat rates this low (CVSS 3.1). Weakness: CWE-115. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.