Complete feed
Security advisories & CVEs
5207 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-27877] Information disclosure of data-source passwords via public dashboards
Information disclosure of data-source passwords via public dashboards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): grafana. Resolved in Red Hat advisory RHSA-2026:11416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.
High [CVE-2026-33433] Authentication bypass via non-canonical HTTP header injection
Authentication bypass via non-canonical HTTP header injection. Red Hat rates this important (CVSS 7.7). Weakness: CWE-290. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.
High [CVE-2026-32695] Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider
Cross-tenant traffic exposure and host restriction bypass via rule-syntax injection in Knative provider. Red Hat rates this important (CVSS 7.7). Weakness: CWE-917. Affected package(s): devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.
High [CVE-2026-27858] denial of service via crafted message before authentication
denial of service via crafted message before authentication. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-27857] denial of service via specially crafted NOOP command
denial of service via specially crafted NOOP command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-27856] Full access via timing oracle attack in credential verification
Full access via timing oracle attack in credential verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-208. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 6.
High [CVE-2026-24031] Authentication bypass and user enumeration due to cleared auth_username_chars configuration
Authentication bypass and user enumeration due to cleared auth_username_chars configuration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.
High [CVE-2025-59032] Denial of Service via crafted SASL initial response in AUTHENTICATE command
Denial of Service via crafted SASL initial response in AUTHENTICATE command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-229. Affected package(s): dovecot. Resolved in Red Hat advisory RHSA-2026:26564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-33747] Arbitrary file write and code execution via untrusted frontend
Arbitrary file write and code execution via untrusted frontend. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-22. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1776240392, quay/quay-rhel9:1779922205, multicluster-engine/must-gather-rhel9:1782158798, openshift-service-mesh/istio-proxyv2-rhel9:1776291540, openshift-service-mesh/istio-proxyv2-rhel9:1776315466, oadp/oadp-mustgather-rhel9:1779770049. Resolved in Red Hat advisory RHSA-2026:9453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33721] Denial of Service via crafted Styled Layer Descriptor
Denial of Service via crafted Styled Layer Descriptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33701] io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI
io.opentelemetry.javaagent/opentelemetry-javaagent: OpenTelemetry Java Instrumentation: Remote code execution via deserialization vulnerability in RMI. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-33748] Unauthorized file access via Git URL fragment subdir components
Unauthorized file access via Git URL fragment subdir components. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1776240392, multicluster-engine/must-gather-rhel9:1782158798, openshift-service-mesh/istio-proxyv2-rhel9:1776291540, openshift-service-mesh/istio-proxyv2-rhel9:1776315466, oadp/oadp-mustgather-rhel9:1779770049, oadp/oadp-mustgather-rhel9:1779770057. Resolved in Red Hat advisory RHSA-2026:9453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-4948] Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-279. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Under investigation: Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHBA-2026:28238.
Critical [CVE-2026-33945] Privilege escalation and denial of service via path traversal in systemd credential configuration
Privilege escalation and denial of service via path traversal in systemd credential configuration. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-33897] Arbitrary file read/write as root via pongo2 template chroot bypass
Arbitrary file read/write as root via pongo2 template chroot bypass. Red Hat rates this important (CVSS 9.1). Weakness: CWE-243. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27893] Remote code execution due to hardcoded trust_remote_code setting
Remote code execution due to hardcoded trust_remote_code setting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Affected package(s): rhaiis/vllm-cuda-rhel9:1779223654, rhelai3/bootc-azure-cuda-rhel9:1776871985, rhelai3/bootc-aws-cuda-rhel9:1776871984, rhaiis/model-opt-cuda-rhel9:1775749857, rhaiis/vllm-rocm-rhel9:1775680262, rhaiis/vllm-rocm-rhel9:1779223651. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat Enterprise Linux AI 3.3; Red Hat OpenShift AI 2.25; and 1 more.
High [CVE-2026-33898] Privilege escalation and unauthorized access due to improper authentication token validation in web UI
Privilege escalation and unauthorized access due to improper authentication token validation in web UI. Red Hat rates this important (CVSS 8.2). Weakness: CWE-303. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33711] Local privilege escalation or denial of service via predictable temporary file paths
Local privilege escalation or denial of service via predictable temporary file paths. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33542] Image cache poisoning due to insufficient image fingerprint validation
Image cache poisoning due to insufficient image fingerprint validation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-354. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-1556] File (Field) Paths: Drupal File (Field) Paths: Information Disclosure via filename-collision uploads
File (Field) Paths: Drupal File (Field) Paths: Information Disclosure via filename-collision uploads. Red Hat rates this important (CVSS 7.7). Weakness: CWE-73. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.