Complete feed
Security advisories & CVEs
5194 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-4442] Heap buffer overflow in CSS
Heap buffer overflow in CSS. Red Hat rates this important (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4439] Out of bounds memory access in WebGL
Out of bounds memory access in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4452] Integer overflow in ANGLE
Integer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4440] Out of bounds read and write in WebGL
Out of bounds read and write in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4458] Use after free in Extensions
Use after free in Extensions. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4449] Use after free in Blink
Use after free in Blink. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4444] Stack buffer overflow in WebRTC
Stack buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4443] Heap buffer overflow in WebAudio
Heap buffer overflow in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4459] Out of bounds read and write in WebAudio
Out of bounds read and write in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4456] Use after free in Digital Credentials API
Use after free in Digital Credentials API. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-4463] Heap buffer overflow in WebRTC
Heap buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-15031] Path Traversal Vulnerability in mlflow/mlflow
Path Traversal Vulnerability in mlflow/mlflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-32636] Denial of Service via out-of-bounds write in NewXMLTree method
Denial of Service via out-of-bounds write in NewXMLTree method. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:17618 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-31963] Arbitrary code execution via crafted CRAM file
Arbitrary code execution via crafted CRAM file. Red Hat rates this important (CVSS 7.3). Weakness: CWE-193. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31962] Heap buffer overflow leading to arbitrary code execution via crafted CRAM file
Heap buffer overflow leading to arbitrary code execution via crafted CRAM file. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27135] Denial of Service via malformed HTTP/2 frames after session termination
Denial of Service via malformed HTTP/2 frames after session termination. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected package(s): rhcos, nodejs:20, rhpam, rhaiis/vllm-cuda-rhel9:1778274666, nghttp2, rhui5/haproxy-rhel9:1776868744. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Core Services on RHEL 7 Server; Red Hat JBoss Core Services on RHEL 8; Red Hat OpenShift Container Platform 4.12; Middleware Containers for OpenShift; and 57 more.
High [CVE-2026-33001] Arbitrary file write and potential code execution through crafted archives
Arbitrary file write and potential code execution through crafted archives. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: OpenShift Developer Tools and Services 4.12; OpenShift Developer Tools and Services 4.13; OpenShift Developer Tools and Services 4.14; OpenShift Developer Tools and Services 4.15; and 6 more.
High [CVE-2026-31938] Cross site scripting via unsanitized output options
Cross site scripting via unsanitized output options. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.
High [CVE-2026-31898] Arbitrary code execution via unsanitized input in createAnnotation method
Arbitrary code execution via unsanitized input in createAnnotation method. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.
High [CVE-2026-30922] pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
pyasn1 Vulnerable to Denial of Service via Unbounded Recursion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): ansible-automation-platform, rhelai3/bootc-rocm-rhel9:1778666124, rhaiis/vllm-rocm-rhel9:1778244531, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, fence-agents. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; and 28 more.