Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

7850 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Red Hat Updated

Medium [CVE-2026-53586] Information disclosure via HTTP redirect allows credential leakage

Information disclosure via HTTP redirect allows credential leakage. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53586
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-53583] Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison

Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53583
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-53585] Denial of Service via Unbounded Memory Allocation

Denial of Service via Unbounded Memory Allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53585
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-63379] HTTP header smuggling allows authorization bypass or cache poisoning

HTTP header smuggling allows authorization bypass or cache poisoning. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63379
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.7Red Hat Updated

Medium [CVE-2026-63380] Denial of Service via Null Pointer Dereference

Denial of Service via Null Pointer Dereference. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63380
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.6Red Hat Updated

Medium [CVE-2026-63381] Memory corruption due to use-after-free

Memory corruption due to use-after-free. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63381
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-71492] Arbitrary file write via path traversal

Arbitrary file write via path traversal. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22.

CVE-2026-71492
Unclassified
Aug 20, 2026
Medium6.5Red Hat

Medium [CVE-2026-73199] NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value

NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.

CVE-2026-73199
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.3Red Hat

Medium [CVE-2026-73196] Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding

Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.

CVE-2026-73196
Red Hat Enterprise Linux
Aug 20, 2026
Medium5.3Red Hat

Medium [CVE-2026-77014] Libsoup: libsoup: integer truncation in sort_ranges comparator causes silent omission of http range responses

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB. A remote attacker can exploit this to cause the server to silently omit requested byte ranges from responses. Exploitation requires the server to be serving resources larger than approximately 2 GB, which limits real-world impact. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-197. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3; Red Hat package: gnome-clocks; Red Hat package: podman.

CVE-2026-77014
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.9Red Hat Updated

Medium [CVE-2026-76957] Memory corruption vulnerability allows arbitrary code execution or denial of service

Memory corruption vulnerability allows arbitrary code execution or denial of service. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: expat; and 5 more.

CVE-2026-76957
Red Hat Enterprise Linux
Aug 20, 2026
Medium5.9Red Hat Updated

Medium [CVE-2026-76956] Denial of Service via hash flooding attack with crafted XML

Denial of Service via hash flooding attack with crafted XML. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-331. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-76956
Unclassified
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-43804] Visiting a website may lead to an app denial-of-service

Visiting a website may lead to an app denial-of-service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-664. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-43804
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-64713] Websites may know if the user has visited a given link

Websites may know if the user has visited a given link. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-200. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64713
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-64728] Maliciously crafted web content may violate iframe sandboxing policy

Maliciously crafted web content may violate iframe sandboxing policy. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-693. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64728
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-64730] Visiting a website that frames malicious content may lead to UI spoofing

Visiting a website that frames malicious content may lead to UI spoofing. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-451. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64730
Red Hat Enterprise Linux
Aug 20, 2026
Low2.2Red Hat Updated

Low [CVE-2026-77648] Server-Side Request Forgery allows internal URL access by administrators

Server-Side Request Forgery allows internal URL access by administrators. Red Hat rates this low (CVSS 2.2). Weakness: CWE-918.

CVE-2026-77648
Unclassified
Aug 20, 2026
Low3.5Red Hat Updated

Low [CVE-2026-53584] Submodule path traversal allows arbitrary directory creation

Submodule path traversal allows arbitrary directory creation. Red Hat rates this low (CVSS 3.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53584
Red Hat Enterprise Linux
Aug 20, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-70496] operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork

operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork. Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-70496
Unclassified
Aug 19, 2026
Critical9.1Vendor: HighRed Hat Updated

Critical [CVE-2026-71470] Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA

Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA. Red Hat rates this important (CVSS 9.1). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71470
Unclassified
Aug 19, 2026