Complete feed
Security advisories & CVEs
5197 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-23865] Information disclosure or denial of service via specially crafted font files
Information disclosure or denial of service via specially crafted font files. Red Hat rates this moderate (CVSS 5.3). Affected package(s): java, freetype-main. Resolved in Red Hat advisory RHSA-2026:11822 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-3441] Information disclosure via specially crafted XCOFF object file
Information disclosure via specially crafted XCOFF object file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6.
Medium [CVE-2026-3442] Information disclosure or denial of service via out-of-bounds read in bfd linker
Information disclosure or denial of service via out-of-bounds read in bfd linker. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6.
Medium [CVE-2026-3429] Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API
Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-284. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28416] Server-Side Request Forgery allows access to internal services via malicious Space loading
Server-Side Request Forgery allows access to internal services via malicious Space loading. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-28406] Arbitrary code execution via path traversal in build context archive unpacking
Arbitrary code execution via path traversal in build context archive unpacking. Red Hat rates this important (CVSS 8.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2293] Authentication bypass via Fastify path-normalization
Authentication bypass via Fastify path-normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3304] Denial of Service via malformed requests
Denial of Service via malformed requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
High [CVE-2026-2359] Denial of Service via dropped file upload connections
Denial of Service via dropped file upload connections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
High [CVE-2026-28364] Remote code execution via buffer over-read in Marshal deserialization
Remote code execution via buffer over-read in Marshal deserialization. Red Hat rates this important (CVSS 7.9). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-28421] Denial of service and information disclosure via crafted swap file
Denial of service and information disclosure via crafted swap file. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.
Medium [CVE-2026-28417] Arbitrary code execution via OS command injection in the netrw plugin
Arbitrary code execution via OS command injection in the netrw plugin. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.
High [CVE-2026-27970] @angular/core: Angular: Cross-site scripting via compromised translation files
@angular/core: Angular: Cross-site scripting via compromised translation files. Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7.
High [CVE-2026-27959] Host header injection vulnerability due to malformed HTTP Host header parsing
Host header injection vulnerability due to malformed HTTP Host header parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-20. Affected package(s): rhoai/odh-mod-arch-model-registry-rhel9:1776742141, rhoai/odh-dashboard-rhel9:1776742021, openshift4/ose-monitoring-plugin-rhel9:1775577192. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift Container Platform 4.19; Red Hat Developer Hub.
High [CVE-2026-27942] Stack overflow leads to Denial of Service
Stack overflow leads to Denial of Service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): odf4/mcg-core-rhel9:1776403991, odf4/mcg-rhel9-operator:1776404009, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, odf4/odf-external-snapshotter-rhel9-operator:1776406284, odf4/odf-external-snapshotter-sidecar-rhel9:1776406291, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27896] improper handling of case sensitivity
improper handling of case sensitivity. Red Hat rates this important (CVSS 7.2). Weakness: CWE-178. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Serverless; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-27830] Arbitrary Code Execution via deserialization of crafted objects
Arbitrary Code Execution via deserialization of crafted objects. Red Hat rates this important (CVSS 8). Weakness: CWE-502. Affected package(s): com.mchange/c3p0, org.hibernate.orm/hibernate-c3p0, eap8-hibernate, c3p0/c3p0, candlepin. Resolved in Red Hat advisory RHSA-2026:28385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; Red Hat build of Debezium 2; and 3 more.
Medium [CVE-2026-27141] Denial of Service due to malformed HTTP/2 frames
Denial of Service due to malformed HTTP/2 frames. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): openshift-pipelines/pipelines-operator-bundle:1781686494, openshift-pipelines/pipelines-rhel9-operator:1780645012, golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27904] Denial of Service via catastrophic backtracking in glob expressions
Denial of Service via catastrophic backtracking in glob expressions. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Affected package(s): quay/quay-rhel9:1775069491, nodejs:20, nodejs:22, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, devspaces/openvsx-rhel9:1779528224, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-27888] Denial of Service via crafted PDF
Denial of Service via crafted PDF. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.