Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5201 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3Linux

Medium [CVE-2026-29775] FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId

FreeRDP has a heap-buffer-overflow in bitmap_cache_put via OOB cacheId. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19142 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-29775
Unclassified
Mar 13, 2026
Medium6.5Linux

Medium [CVE-2026-2673] OpenSSL TLS 1.3 server may choose unexpected key agreement group

OpenSSL TLS 1.3 server may choose unexpected key agreement group. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-325. Affected package(s): openssl-main, jbcs-httpd24-openssl. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2673
Unclassified
Mar 13, 2026
Medium6.4Vendor: HighLinux

Medium [CVE-2025-8766] Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container

Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container. Red Hat rates this important (CVSS 6.4). Weakness: CWE-276. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.22.

CVE-2025-8766
Unclassified
Mar 13, 2026
Medium6.7Linux

Medium [CVE-2026-4105] Privilege escalation via improper access control in RegisterMachine D-Bus method

Privilege escalation via improper access control in RegisterMachine D-Bus method. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-284. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4105
Unclassified
Mar 13, 2026
High7.5Linux

High [CVE-2026-32597] PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation). Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): ansible-automation-platform, python3.12-pyjwt, quay/quay-rhel8:1775169155, quay/quay-rhel8:1775253092, fence-agents, rhelai3/bootc-aws-cuda-rhel9:1776871984. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; and 17 more.

CVE-2026-32597
Red Hat Enterprise Linux
Mar 12, 2026
High7.5Linux

High [CVE-2026-32304] Arbitrary code execution via unsanitized parameters in create_function

Arbitrary code execution via unsanitized parameters in create_function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Logging Subsystem for Red Hat OpenShift.

CVE-2026-32304
Unclassified
Mar 12, 2026
High7.5Linux

High [CVE-2026-2229] Denial of Service via invalid WebSocket permessage-deflate extension parameter

Denial of Service via invalid WebSocket permessage-deflate extension parameter. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.

CVE-2026-2229
Red Hat Enterprise Linux
Mar 12, 2026
High7.5Linux

High [CVE-2026-1528] Denial of Service via crafted WebSocket frame with large length

Denial of Service via crafted WebSocket frame with large length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.

CVE-2026-1528
Red Hat Enterprise Linux
Mar 12, 2026
High7.5Linux

High [CVE-2026-1526] Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression

Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.

CVE-2026-1526
Red Hat Enterprise Linux
Mar 12, 2026
High7.3Vendor: MediumLinux

High [CVE-2026-1525] HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers

HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-444. Affected package(s): nodejs:22, cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0, rhdh/rhdh-hub-rhel9:1776784286, devspaces/code-rhel9:1779814592, nodejs:24, cryostat/cryostat-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-1525
Unclassified
Mar 12, 2026
High7.5Linux

High [CVE-2026-32274] Arbitrary file writes from unsanitized user input in cache file name

Arbitrary file writes from unsanitized user input in cache file name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): ansible-automation-platform, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1776319179, rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1776319275, rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1776318795, rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1776319193, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1776319185. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; OpenShift Lightspeed; and 3 more.

CVE-2026-32274
Unclassified
Mar 12, 2026
High8.2Linux

High [CVE-2026-3497] Information disclosure or denial of service due to uninitialized variables

Information disclosure or denial of service due to uninitialized variables. Red Hat rates this important (CVSS 8.2). Weakness: CWE-824. Affected package(s): openssh, rhcos, rhpam, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhui5/installer-rhel9:1776868772. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Middleware Containers for OpenShift; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; and 52 more.

CVE-2026-3497
Red Hat Enterprise Linux
Mar 12, 2026
High7.5Linux

High [CVE-2026-32141] Unbounded recursion DoS in parse() revive phase

Unbounded recursion DoS in parse() revive phase. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, devspaces/dashboard-rhel9:1779341289, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-dashboard-rhel8:1774282136, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat Edge Manager 1.0; Red Hat OpenShift AI 2.16; and 9 more.

CVE-2026-32141
Unclassified
Mar 12, 2026
High7.5Linux

High [CVE-2026-28356] denial of service via maliciously crafted HTTP or multipart segment headers

denial of service via maliciously crafted HTTP or multipart segment headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): rhaiis/vllm-cuda-rhel9:1774351144, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-caikit-tgis-serving-rhel9:1776247907, rhaiis/vllm-rocm-rhel9:1775252598, rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; and 3 more.

CVE-2026-28356
Red Hat Enterprise Linux
Mar 12, 2026
High8.8Linux Exploited CISA KEV

High [CVE-2026-3909] Out of bounds write in Skia

Out of bounds write in Skia. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3909
Unclassified
Mar 12, 2026
High8.8Linux Exploited CISA KEV

High [CVE-2026-3910] Inappropriate implementation in V8

Inappropriate implementation in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3910
Unclassified
Mar 12, 2026
Medium6.5Linux

Medium [CVE-2026-1527] HTTP header injection and request smuggling vulnerability

HTTP header injection and request smuggling vulnerability. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-93. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-1527
Unclassified
Mar 12, 2026
Medium5.9Linux

Medium [CVE-2026-2581] Denial of Service due to uncontrolled resource consumption

Denial of Service due to uncontrolled resource consumption. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected package(s): nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-2581
Unclassified
Mar 12, 2026
Medium5.9Linux

Medium [CVE-2026-32235] @backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass

@backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-601. Affected package(s): rhdh/rhdh-hub-rhel9:1780930740. Resolved in Red Hat advisory RHSA-2026:24841 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32235
Unclassified
Mar 12, 2026
Low2.5Linux

Low [CVE-2025-13462] `tarfile` module misinterprets crafted tar archives leading to data integrity issues

`tarfile` module misinterprets crafted tar archives leading to data integrity issues. Red Hat rates this low (CVSS 2.5). Weakness: CWE-237. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-13462
Unclassified
Mar 12, 2026