Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5207 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Linux

High [CVE-2026-27877] Information disclosure of data-source passwords via public dashboards

Information disclosure of data-source passwords via public dashboards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): grafana. Resolved in Red Hat advisory RHSA-2026:11416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-27877
Red Hat Enterprise Linux
Mar 27, 2026
High7.7Linux

High [CVE-2026-33433] Authentication bypass via non-canonical HTTP header injection

Authentication bypass via non-canonical HTTP header injection. Red Hat rates this important (CVSS 7.7). Weakness: CWE-290. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.

CVE-2026-33433
Unclassified
Mar 27, 2026
High7.7Linux

High [CVE-2026-32695] Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider

Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider. Red Hat rates this important (CVSS 7.7). Weakness: CWE-917. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.

CVE-2026-32695
Unclassified
Mar 27, 2026
High7.5Linux

High [CVE-2026-27858] denial of service via crafted message before authentication

denial of service via crafted message before authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2026-27858
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-27857] denial of service via specially crafted NOOP command

denial of service via specially crafted NOOP command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2026-27857
Red Hat Enterprise Linux
Mar 27, 2026
High7.4Linux

High [CVE-2026-27856] Full access via timing oracle attack in credential verification

Full access via timing oracle attack in credential verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-208. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 6.

CVE-2026-27856
Red Hat Enterprise Linux
Mar 27, 2026
High7.7Linux

High [CVE-2026-24031] Authentication bypass and user enumeration due to cleared auth_username_chars configuration

Authentication bypass and user enumeration due to cleared auth_username_chars configuration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.

CVE-2026-24031
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2025-59032] Denial of Service via crafted SASL initial response in AUTHENTICATE command

Denial of Service via crafted SASL initial response in AUTHENTICATE command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-229. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2025-59032
Red Hat Enterprise Linux
Mar 27, 2026
High8.2Vendor: MediumLinux

High [CVE-2026-33747] Arbitrary file write and code execution via untrusted frontend

Arbitrary file write and code execution via untrusted frontend. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-22. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1776240392, quay/quay-rhel9:1779922205, multicluster-engine/must-gather-rhel9:1782158798, openshift-service-mesh/istio-proxyv2-rhel9:1776291540, openshift-service-mesh/istio-proxyv2-rhel9:1776315466, oadp/oadp-mustgather-rhel9:1779770049. Resolved in Red Hat advisory RHSA-2026:9453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33747
Unclassified
Mar 27, 2026
High7.5Linux

High [CVE-2026-33721] Denial of Service via crafted Styled Layer Descriptor

Denial of Service via crafted Styled Layer Descriptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33721
Unclassified
Mar 27, 2026
High8.1Linux

High [CVE-2026-33701] io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI

io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33701
Unclassified
Mar 27, 2026
Medium6.5Linux

Medium [CVE-2026-33748] Unauthorized file access via Git URL fragment subdir components

Unauthorized file access via Git URL fragment subdir components. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1776240392, multicluster-engine/must-gather-rhel9:1782158798, openshift-service-mesh/istio-proxyv2-rhel9:1776291540, openshift-service-mesh/istio-proxyv2-rhel9:1776315466, oadp/oadp-mustgather-rhel9:1779770049, oadp/oadp-mustgather-rhel9:1779770057. Resolved in Red Hat advisory RHSA-2026:9453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33748
Unclassified
Mar 27, 2026
Medium5.5Linux

Medium [CVE-2026-4948] Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-279. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Under investigation: Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHBA-2026:28238.

CVE-2026-4948
Red Hat Enterprise Linux
Mar 27, 2026
Critical9.6Linux

Critical [CVE-2026-33945] Privilege escalation and denial of service via path traversal in systemd credential configuration

Privilege escalation and denial of service via path traversal in systemd credential configuration. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33945
Unclassified
Mar 26, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-33897] Arbitrary file read/write as root via pongo2 template chroot bypass

Arbitrary file read/write as root via pongo2 template chroot bypass. Red Hat rates this important (CVSS 9.1). Weakness: CWE-243. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33897
Unclassified
Mar 26, 2026
High8.8Linux

High [CVE-2026-27893] Remote code execution due to hardcoded trust_remote_code setting

Remote code execution due to hardcoded trust_remote_code setting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Affected package(s): rhaiis/vllm-cuda-rhel9:1779223654, rhelai3/bootc-azure-cuda-rhel9:1776871985, rhelai3/bootc-aws-cuda-rhel9:1776871984, rhaiis/model-opt-cuda-rhel9:1775749857, rhaiis/vllm-rocm-rhel9:1775680262, rhaiis/vllm-rocm-rhel9:1779223651. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat Enterprise Linux AI 3.3; Red Hat OpenShift AI 2.25; and 1 more.

CVE-2026-27893
Red Hat Enterprise Linux
Mar 26, 2026
High8.2Linux

High [CVE-2026-33898] Privilege escalation and unauthorized access due to improper authentication token validation in web UI

Privilege escalation and unauthorized access due to improper authentication token validation in web UI. Red Hat rates this important (CVSS 8.2). Weakness: CWE-303. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33898
Unclassified
Mar 26, 2026
High8.8Linux

High [CVE-2026-33711] Local privilege escalation or denial of service via predictable temporary file paths

Local privilege escalation or denial of service via predictable temporary file paths. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33711
Unclassified
Mar 26, 2026
High8.5Linux

High [CVE-2026-33542] Image cache poisoning due to insufficient image fingerprint validation

Image cache poisoning due to insufficient image fingerprint validation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-354. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33542
Unclassified
Mar 26, 2026
High7.7Linux

High [CVE-2026-1556] File (Field) Paths: Drupal File (Field) Paths: Information Disclosure via filename-collision uploads

File (Field) Paths: Drupal File (Field) Paths: Information Disclosure via filename-collision uploads. Red Hat rates this important (CVSS 7.7). Weakness: CWE-73. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1556
Unclassified
Mar 26, 2026