Complete feed
Security advisories & CVEs
5192 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-4598] Denial of Service via infinite loop in bnModInverse function with crafted inputs
Denial of Service via infinite loop in bnModInverse function with crafted inputs. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected package(s): quay/quay-rhel8:1779811473, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1779822261, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.
High [CVE-2026-4602] Signature verification bypass via negative exponent handling
Signature verification bypass via negative exponent handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-681. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.
High [CVE-2026-4600] Cryptographic signature forgery via malicious DSA domain parameters
Cryptographic signature forgery via malicious DSA domain parameters. Red Hat rates this important (CVSS 8.2). Weakness: CWE-347. Affected package(s): migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, quay/quay-rhel9:1779204086, migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; Red Hat Quay 3.16; and 1 more.
High [CVE-2026-4680] Use after free in FedCM
Use after free in FedCM. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-33176] Denial of Service via large scientific notation strings
Denial of Service via large scientific notation strings. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): rubygem-activesupport. Resolved in Red Hat advisory RHSA-2026:14835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-26209] Denial of Service due to uncontrolled recursion via crafted CBOR payloads
Denial of Service due to uncontrolled recursion via crafted CBOR payloads. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected package(s): rhaiis/vllm-rocm-rhel9:1779223651, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1779223654, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:19724 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-4647] Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library
Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.
Medium [CVE-2026-4674] Out of bounds read in CSS
Out of bounds read in CSS. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-4675] Heap buffer overflow in WebGL
Heap buffer overflow in WebGL. Red Hat rates this important (CVSS 6.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-4677] Out of bounds read in WebAudio
Out of bounds read in WebAudio. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-33228] Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.
Prototype pollution vulnerability allows arbitrary code execution via crafted JSON.. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-915. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat 3scale API Management Platform 2; Red Hat Build of Keycloak; and 1 more.
Critical [CVE-2026-33210] Denial of Service or Information Disclosure via format string injection
Denial of Service or Information Disclosure via format string injection. Red Hat rates this important (CVSS 9.1). Weakness: CWE-134. Affected package(s): ruby4.0, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:20606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Critical [CVE-2026-33186] Authorization bypass due to improper HTTP/2 path validation
Authorization bypass due to improper HTTP/2 path validation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-551. Affected package(s): rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429, odf4/odf-csi-addons-sidecar-rhel9:1781550957, rhtas/trillian-logserver-rhel9:1776243434, openshift4/ose-cluster-olm-rhel9-operator:1779787336, rhdh/rhdh-rhel9-operator:1774544220, openshift4/ose-csi-driver-nfs-rhel9:1778242571. Resolved in Red Hat advisory RHSA-2026:27893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat Satellite 6.16 for RHEL 8; and 113 more.
Critical [CVE-2026-23537] Unauthenticated Arbitrary File Write
Unauthenticated Arbitrary File Write. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-862. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33236] Arbitrary file overwrite and creation via path traversal in XML index files
Arbitrary file overwrite and creation via path traversal in XML index files. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1776319185, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1776243238, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more.
High [CVE-2026-33231] Denial of Service via unauthenticated remote shutdown
Denial of Service via unauthenticated remote shutdown. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1780069222, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1780069226, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more.
High [CVE-2026-33180] Information disclosure and potential impersonation via HTTP redirects sending sensitive headers
Information disclosure and potential impersonation via HTTP redirects sending sensitive headers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-201. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2026-33154] Arbitrary code execution via Server-Side Template Injection
Arbitrary code execution via Server-Side Template Injection. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-917. Affected package(s): ansible-automation-platform, automation-controller. Resolved in Red Hat advisory RHSA-2026:34160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-33150] Arbitrary code execution via use-after-free in io_uring subsystem
Arbitrary code execution via use-after-free in io_uring subsystem. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-32710] Remote Code Execution or Denial of Service via JSON_SCHEMA_VALID() function vulnerability
Remote Code Execution or Denial of Service via JSON_SCHEMA_VALID() function vulnerability. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-120. Affected package(s): mariadb11.8, galera, mariadb:11.8. Resolved in Red Hat advisory RHSA-2026:19182 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.