Complete feed
Security advisories & CVEs
5196 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-29186] TechDocs Mkdocs configuration key enables arbitrary code execution
TechDocs Mkdocs configuration key enables arbitrary code execution. Red Hat rates this important (CVSS 9.1). Weakness: CWE-791. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
High [CVE-2026-29786] hardlink path traversal via drive-relative linkpath
hardlink path traversal via drive-relative linkpath. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-24281] Impersonation of servers or clients via reverse DNS spoofing
Impersonation of servers or clients via reverse DNS spoofing. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): zookeeper, rhoai/odh-modelmesh-rhel9:1776756834. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat build of Debezium 2; Red Hat build of Debezium 3; Red Hat Fuse 7; and 3 more.
High [CVE-2026-30827] Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking
Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1389. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1774268173, devspaces/openvsx-rhel9:1779528224. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-24308] Information disclosure via improper handling of configuration values
Information disclosure via improper handling of configuration values. Red Hat rates this important (CVSS 3.3). Weakness: CWE-117. Affected package(s): zookeeper, rhoai/odh-modelmesh-rhel9:1776756834. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat build of Debezium 2; Red Hat build of Debezium 3; Red Hat Fuse 7; and 3 more.
Critical [CVE-2026-28802] Signature verification bypass via malicious JWT allows unauthorized access
Signature verification bypass via malicious JWT allows unauthorized access. Red Hat rates this important (CVSS 9.1). Weakness: CWE-347. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1773771962, quay/quay-rhel9:1779204086, quay/quay-rhel8:1773971077, quay/quay-rhel8:1773936323, quay/quay-rhel8:1775169219. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.15; and 3 more.
Critical [CVE-2026-29068] Denial of Service via malformed RTP payload processing
Denial of Service via malformed RTP payload processing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25679] Incorrect parsing of IPv6 host literals in net/url
Incorrect parsing of IPv6 host literals in net/url. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift-service-mesh/istio-cni-rhel8:1777374598, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-oauth-server-rhel9:1779253952, openshift4/ose-tests:1777002345. Resolved in Red Hat advisory RHSA-2026:11749 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat OpenShift Container Platform 4.12; and 136 more.
High [CVE-2026-27137] Incorrect enforcement of email constraints in crypto/x509
Incorrect enforcement of email constraints in crypto/x509. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected package(s): rhc-worker-playbook, golang1, golang, openshift-gitops, rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator:1.0.2, delve. Resolved in Red Hat advisory RHSA-2026:28047 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenStack Platform 17.1 for RHEL 9; RHEM 1.0 for RHEL 9; and 59 more.
High [CVE-2026-29063] Arbitrary code execution via Prototype Pollution
Arbitrary code execution via Prototype Pollution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1776151134, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, openshift4/ose-networking-console-plugin-rhel9:1778517109. Resolved in Red Hat advisory RHSA-2026:9848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.8; and 50 more.
High [CVE-2026-29091] Remote Code Execution via insecure callback function implementation
Remote Code Execution via insecure callback function implementation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Logging Subsystem for Red Hat OpenShift.
High [CVE-2026-29089] Arbitrary code execution via malicious functions in user-writable schemas during extension upgrade
Arbitrary code execution via malicious functions in user-writable schemas during extension upgrade. Red Hat rates this important (CVSS 8.8). Weakness: CWE-427. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-26017] DNS access control bypass due to plugin execution order flaw
DNS access control bypass due to plugin execution order flaw. Red Hat rates this important (CVSS 7.7). Weakness: CWE-367. Affected package(s): rhacm2/lighthouse-coredns-rhel9:1774086225, rhacm2/lighthouse-agent-rhel9:1780204232, rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:8151 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Connectivity Link 1.
High [CVE-2026-26018] Denial of Service vulnerability due to predictable pseudo-random number generation
Denial of Service vulnerability due to predictable pseudo-random number generation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1241. Affected package(s): rhacm2/lighthouse-coredns-rhel9:1774086225, rhacm2/lighthouse-agent-rhel9:1780204232, rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:8151 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Connectivity Link 1.
High [CVE-2026-29074] Denial of Service via XML entity expansion
Denial of Service via XML entity expansion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, rhoai/odh-dashboard-rhel8:1774282136, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, automation-gateway. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Security for Kubernetes 4.8; and 28 more.
High [CVE-2026-29062] Denial of Service via excessive JSON nesting
Denial of Service via excessive JSON nesting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28799] Denial of Service via heap use-after-free in event subscription
Denial of Service via heap use-after-free in event subscription. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27142] URLs in meta content attribute actions are not escaped in html/template
URLs in meta content attribute actions are not escaped in html/template. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7291 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-27139] FileInfo can escape from a Root in golang os module
FileInfo can escape from a Root in golang os module. Red Hat rates this low (CVSS 2.5). Weakness: CWE-22. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-27138] Panic in name constraint checking for malformed certificates in crypto/x509
Panic in name constraint checking for malformed certificates in crypto/x509. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7291 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.