Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low2.9Red Hat

Low [CVE-2026-61867] Denial of Service due to memory leak in TIFF encoder

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service. A flaw was found in ImageMagick. A remote attacker could exploit a memory leak vulnerability within the TIFF encoder. This can result in a denial of service (DoS), making the affected system or application unavailable. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61867
Red Hat Enterprise Linux
Jul 15, 2026
Low2.9Red Hat

Low [CVE-2026-61865] Memory leak in hough lines operation can lead to denial of service

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. A flaw was found in ImageMagick. When processing images, a memory leak can occur during the 'hough lines' operation if an internal process fails. This vulnerability could lead to a gradual depletion of system memory, potentially resulting in a denial of service (DoS) for the affected system. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61865
Red Hat Enterprise Linux
Jul 15, 2026
Low2.9Red Hat

Low [CVE-2026-61866] Memory leak in JNG encoder can lead to denial of service

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion. A flaw was found in ImageMagick. A memory leak vulnerability exists in the JNG (JPEG Network Graphics) encoder when the application fails to open a blob. A remote attacker could exploit this by providing specially crafted malformed JNG files, leading to resource exhaustion and a denial of service (DoS) for the affected system. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61866
Red Hat Enterprise Linux
Jul 15, 2026
Low2.9Red Hat

Low [CVE-2026-61864] Memory leak in color transformation to log colorspace

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory is not released. A flaw was found in ImageMagick. This vulnerability, which can be triggered by a local attacker without requiring special privileges or user interaction, may lead to a denial of service due to unreleased memory. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61864
Red Hat Enterprise Linux
Jul 15, 2026
Low2.9Red Hat

Low [CVE-2026-61863] Memory leak in TIFF encoder

ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting in a small memory leak. A flaw was found in ImageMagick. When processing a Tagged Image File Format (TIFF) image, a small memory leak can occur if the TIFF encoder is unable to create a temporary file. This can lead to a gradual consumption of system memory, potentially impacting the availability of the application. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61863
Red Hat Enterprise Linux
Jul 15, 2026
Low2.9Red Hat

Low [CVE-2026-61862] Information disclosure via out-of-bounds read when displaying profiles with debug enabled

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled. A flaw was found in ImageMagick. This occurs due to an out-of-bounds read, where a single byte beyond the profile's boundary can be unintentionally printed. This could potentially expose sensitive data. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61862
Red Hat Enterprise Linux
Jul 15, 2026
Low3.7Red Hat

Low [CVE-2026-61860] Denial of Service via use-after-free during freetype initialization

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory that was already freed. This can be triggered during image processing and may lead to a denial of service. This vulnerability, a use-after-free, occurs when the freetype library fails to initialize, causing the software to continue processing with freed memory. A remote attacker could exploit this during image processing, leading to a denial of service (DoS) condition, which would make the service unavailable to legitimate users. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61860
Red Hat Enterprise Linux
Jul 15, 2026
LowRed Hat

Low [CVE-2026-61464] ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61464
Red Hat Enterprise Linux
Jul 15, 2026
Low3.3Red Hat

Low [CVE-2026-61859] Information disclosure via policy bypass in -script operation

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy. A flaw was found in ImageMagick. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-639. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-61859
Red Hat Enterprise Linux
Jul 15, 2026
Low3.7Red Hat

Low [CVE-2026-56764] Hono - Timing Attack in basicAuth and bearerAuth Middleware

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements. A flaw was found in Hono. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-208. Affected Red Hat products: Red Hat Hardened Images; Migration Toolkit for Applications 8. Red Hat lists Red Hat Ansible Automation Platform 2; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat OpenShift Dev Spaces as not affected. Red Hat fixing advisory: RHSA-2026:47618, RHSA-2026:47619.

CVE-2026-56764
Unclassified
Jul 15, 2026
Low3.3Red Hat

Low [CVE-2026-56375] Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Ma…

ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service. A flaw was found in ImageMagick. An attacker can exploit this by triggering failed actions, leading to the exhaustion of memory resources. This can result in a denial of service (DoS), making the affected system or application unavailable to legitimate users. Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification:. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-56375
Red Hat Enterprise Linux
Jul 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-15773] Use after free in Core

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the Core component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15773
Unclassified
Jul 14, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-15775] Insufficient policy enforcement in V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) An insufficient policy enforcement flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-346.

CVE-2026-15775
Unclassified
Jul 14, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-15774] Use after free in Skia

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-15774
Unclassified
Jul 14, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-54058] Memory disclosure or denial of service via crafted McIdas AREA image

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0. A remote attacker who can supply such an image to a service that loads it without user interaction may disclose adjacent process memory or trigger a denial of service. Red Hat severity: Important — CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; and 16 more.

CVE-2026-54058
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-59733] Unauthorized access to private repositories via directory traversal

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include.. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4. A flaw was found in Rclone. This vulnerability can lead to significant information disclosure, data integrity issues, and denial of service for other users' data. By using directory traversal sequences in requests, an attacker can access, modify, or delete other users' private repositories. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-22.

CVE-2026-59733
Unclassified
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-50651] SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM

Allocation of resources without limits or throttling in.NET allows an unauthorized attacker to deny service over a network..NET Denial of Service Vulnerability - HTTP/2 SETTINGS/PING ACK flood causing OOM Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images. Red Hat lists Red Hat Hardened Images as not affected. Red Hat fixing advisory: RHSA-2026:41893, RHSA-2026:41895, RHSA-2026:41897, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:41899, RHSA-2026:41900, RHSA-2026:41901, RHSA-2026:41894, RHSA-2026:41896, RHSA-2026:41898, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:26638, RHSA-2026:27171, RHSA-2026:42145. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-50651
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-54572] Arbitrary file write via malicious symbolic link handling

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as.rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4. A remote attacker could exploit this by providing a malicious symlink, allowing subsequent file writes to occur outside the intended destination with content chosen by the attacker. This could lead to unauthorized modification of files on the system. Rclone's -l/--links option serializes symbolic links encountered during a sync as `.rclonelink` text objects containing the link target, and later recreates those links on the destination. Prior to 1.74.4, rclone did not validate that a stored link target stays within the intended destination tree before recreating it. A remote storage backend under an attacker's control can therefore supply a crafted `.rclonelink` object whose target escapes the destination directory (e.g. via a `../` traversal or an absolute path), causing a subsequent write during the same or a later sync to be redirected outside the intended destination with attacker-chosen content.

CVE-2026-54572
Unclassified
Jul 14, 2026
High7.4Red Hat

High [CVE-2026-45363] Authentication bypass due to empty key in HMAC verification

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty key and no empty-key precondition exists in the HMAC algorithm. The same path is reached when a keyfinder block or key_finder: argument returns an empty string, nil, or an array containing nil for an unknown key, affecting HS256, HS384, and HS512 verification through JWT.decode and JWT::EncodedToken#verify_signature!. This issue is fixed in versions 2.10.3 and 3.2.0. A remote attacker can exploit this vulnerability by crafting a malicious token that is accepted due to an empty key being used in the HMAC (Hash-based Message Authentication Code) digest calculation during token verification. This allows the attacker to bypass authentication and integrity checks, potentially leading to unauthorized access or data manipulation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-347. Affected Red Hat products: Red Hat Satellite 6. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-45363
Unclassified
Jul 14, 2026
High7.5Red Hat

High [CVE-2026-49477] Denial of Service via crafted CSS selector strings

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup.select() /.select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4. A remote attacker can exploit this by supplying a small, specially crafted CSS selector string to applications that process untrusted CSS, potentially blocking worker threads and causing a complete service denial in affected Red Hat products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333. Affected Red Hat products: Red Hat Hardened Images; Red Hat OpenShift AI 3.4; Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Virtualization 4; Red Hat Quay 3. Will not fix / out of support: Red Hat Ansible Automation Platform 2. Red Hat fixing advisory: RHSA-2026:34119, RHSA-2026:60520.

CVE-2026-49477
Unclassified
Jul 14, 2026