Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5197 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.3Linux

Medium [CVE-2026-23865] Information disclosure or denial of service via specially crafted font files

Information disclosure or denial of service via specially crafted font files. Red Hat rates this moderate (CVSS 5.3). Affected package(s): java, freetype-main. Resolved in Red Hat advisory RHSA-2026:11822 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23865
Unclassified
Mar 2, 2026
Medium6.1Linux

Medium [CVE-2026-3441] Information disclosure via specially crafted XCOFF object file

Information disclosure via specially crafted XCOFF object file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6.

CVE-2026-3441
Red Hat Enterprise Linux
Mar 2, 2026
Medium6.1Linux

Medium [CVE-2026-3442] Information disclosure or denial of service via out-of-bounds read in bfd linker

Information disclosure or denial of service via out-of-bounds read in bfd linker. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6.

CVE-2026-3442
Red Hat Enterprise Linux
Mar 2, 2026
Medium4.2Linux

Medium [CVE-2026-3429] Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API

Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-284. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3429
Unclassified
Mar 2, 2026
High8.2Linux

High [CVE-2026-28416] Server-Side Request Forgery allows access to internal services via malicious Space loading

Server-Side Request Forgery allows access to internal services via malicious Space loading. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28416
Unclassified
Feb 27, 2026
High8.5Linux

High [CVE-2026-28406] Arbitrary code execution via path traversal in build context archive unpacking

Arbitrary code execution via path traversal in build context archive unpacking. Red Hat rates this important (CVSS 8.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28406
Unclassified
Feb 27, 2026
High7.5Linux

High [CVE-2026-2293] Authentication bypass via Fastify path-normalization

Authentication bypass via Fastify path-normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2293
Unclassified
Feb 27, 2026
High7.5Linux

High [CVE-2026-3304] Denial of Service via malformed requests

Denial of Service via malformed requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.

CVE-2026-3304
Unclassified
Feb 27, 2026
High7.5Linux

High [CVE-2026-2359] Denial of Service via dropped file upload connections

Denial of Service via dropped file upload connections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.

CVE-2026-2359
Unclassified
Feb 27, 2026
High7.9Linux

High [CVE-2026-28364] Remote code execution via buffer over-read in Marshal deserialization

Remote code execution via buffer over-read in Marshal deserialization. Red Hat rates this important (CVSS 7.9). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-28364
Red Hat Enterprise Linux
Feb 27, 2026
Medium5.3Linux

Medium [CVE-2026-28421] Denial of service and information disclosure via crafted swap file

Denial of service and information disclosure via crafted swap file. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.

CVE-2026-28421
Unclassified
Feb 27, 2026
Medium4.4Linux

Medium [CVE-2026-28417] Arbitrary code execution via OS command injection in the netrw plugin

Arbitrary code execution via OS command injection in the netrw plugin. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.

CVE-2026-28417
Unclassified
Feb 27, 2026
High7.1Linux

High [CVE-2026-27970] @angular/core: Angular: Cross-site scripting via compromised translation files

@angular/core: Angular: Cross-site scripting via compromised translation files. Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7.

CVE-2026-27970
Red Hat Enterprise Linux
Feb 26, 2026
High8.2Linux

High [CVE-2026-27959] Host header injection vulnerability due to malformed HTTP Host header parsing

Host header injection vulnerability due to malformed HTTP Host header parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-20. Affected package(s): rhoai/odh-mod-arch-model-registry-rhel9:1776742141, rhoai/odh-dashboard-rhel9:1776742021, openshift4/ose-monitoring-plugin-rhel9:1775577192. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift Container Platform 4.19; Red Hat Developer Hub.

CVE-2026-27959
Unclassified
Feb 26, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-27942] Stack overflow leads to Denial of Service

Stack overflow leads to Denial of Service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): odf4/mcg-core-rhel9:1776403991, odf4/mcg-rhel9-operator:1776404009, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, odf4/odf-external-snapshotter-rhel9-operator:1776406284, odf4/odf-external-snapshotter-sidecar-rhel9:1776406291, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27942
Unclassified
Feb 26, 2026
High7.2Linux

High [CVE-2026-27896] improper handling of case sensitivity

improper handling of case sensitivity. Red Hat rates this important (CVSS 7.2). Weakness: CWE-178. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Serverless; Red Hat OpenShift AI (RHOAI).

CVE-2026-27896
Unclassified
Feb 26, 2026
High8.0Linux

High [CVE-2026-27830] Arbitrary Code Execution via deserialization of crafted objects

Arbitrary Code Execution via deserialization of crafted objects. Red Hat rates this important (CVSS 8). Weakness: CWE-502. Affected package(s): com.mchange/c3p0, org.hibernate.orm/hibernate-c3p0, eap8-hibernate, c3p0/c3p0, candlepin. Resolved in Red Hat advisory RHSA-2026:28385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; Red Hat build of Debezium 2; and 3 more.

CVE-2026-27830
Red Hat Enterprise Linux
Feb 26, 2026
Medium5.3Linux

Medium [CVE-2026-27141] Denial of Service due to malformed HTTP/2 frames

Denial of Service due to malformed HTTP/2 frames. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): openshift-pipelines/pipelines-operator-bundle:1781686494, openshift-pipelines/pipelines-rhel9-operator:1780645012, golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27141
Unclassified
Feb 26, 2026
Medium6.5Linux

Medium [CVE-2026-27904] Denial of Service via catastrophic backtracking in glob expressions

Denial of Service via catastrophic backtracking in glob expressions. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Affected package(s): quay/quay-rhel9:1775069491, nodejs:20, nodejs:22, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, devspaces/openvsx-rhel9:1779528224, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-27904
Unclassified
Feb 26, 2026
Medium5.3Linux

Medium [CVE-2026-27888] Denial of Service via crafted PDF

Denial of Service via crafted PDF. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27888
Unclassified
Feb 26, 2026