Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5208 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.2Linux

Medium [CVE-2026-0598] Broken Object Level Authorization Leading to Cross-User AI Conversation Context Injection in Ansible Lightspeed API

Broken Object Level Authorization Leading to Cross-User AI Conversation Context Injection in Ansible Lightspeed API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-283. Affected package(s): ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:13545 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0598
Unclassified
Feb 6, 2026
High7.4Vendor: MediumLinux

High [CVE-2025-68121] Incorrect certificate validation during TLS session resumption

Incorrect certificate validation during TLS session resumption. Red Hat rates this moderate (CVSS 7.4). Affected package(s): openshift4/openshift-route-controller-manager-rhel8:1781867531, openshift4/ose-gcp-cloud-controller-manager-rhel9:1781927538, openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/oc-mirror-plugin-rhel8:1781822901, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099. Resolved in Red Hat advisory RHSA-2026:5968 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2025-68121
Unclassified
Feb 5, 2026
High7.4Linux

High [CVE-2025-61732] Go cgo: Code smuggling due to comment parsing discrepancy

Go cgo: Code smuggling due to comment parsing discrepancy. Red Hat rates this important (CVSS 7.4). Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099, openshift4/ose-azure-file-csi-driver-operator-rhel9:1773363768, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-tests:1777002345. Resolved in Red Hat advisory RHSA-2026:3469 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream AUS (v. 8.2); and 41 more.

CVE-2025-61732
Red Hat Enterprise Linux
Feb 5, 2026
Medium5.3Linux

Medium [CVE-2025-47911] Quadratic parsing complexity in golang.org/x/net/html

Quadratic parsing complexity in golang.org/x/net/html. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-400. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1782844225, golang1, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1782839658, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-47911
Unclassified
Feb 5, 2026
Medium4.3Linux

Medium [CVE-2025-58190] Infinite parsing loop in golang.org/x/net

Infinite parsing loop in golang.org/x/net. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-835. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1782844225, golang1, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1782839658, multicluster-engine/hive-rhel9:1770693331, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-58190
Unclassified
Feb 5, 2026
Critical9.3Linux

Critical [CVE-2026-25521] Locutus is vulnerable to Prototype Pollution

Locutus is vulnerable to Prototype Pollution. Red Hat rates this critical (CVSS 9.3). Weakness: CWE-915. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-25521
Unclassified
Feb 4, 2026
High7.1Linux

High [CVE-2026-25536] @modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak

@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak. Red Hat rates this important (CVSS 7.1). Weakness: CWE-367. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1772196222. Resolved in Red Hat advisory RHSA-2026:3960 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Ansible Automation Platform 2.6.

CVE-2026-25536
Unclassified
Feb 4, 2026
High7.0Linux

High [CVE-2026-23074] Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation

Linux kernel: Use-after-free in teql queueing discipline can lead to privilege escalation. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3634 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 6 more.

CVE-2026-23074
Red Hat Enterprise Linux
Feb 4, 2026
High7.4Vendor: MediumLinux

High [CVE-2026-23066] Linux kernel: Denial of Service via unsafe requeue in rxrpc_recvmsg

Linux kernel: Denial of Service via unsafe requeue in rxrpc_recvmsg. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9112 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23066
Unclassified
Feb 4, 2026
High7.6Vendor: MediumLinux

High [CVE-2026-23040] fix typo in frequency notification

fix typo in frequency notification. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:18134 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23040
Unclassified
Feb 4, 2026
High7.3Vendor: MediumLinux

High [CVE-2026-23097] Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration

Linux kernel: Denial of Service due to a deadlock in hugetlb folio migration. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-833. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23097
Unclassified
Feb 4, 2026
Medium5.3Linux

Medium [CVE-2025-22873] Information disclosure via path traversal using specially crafted filenames

Information disclosure via path traversal using specially crafted filenames. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-22873
Unclassified
Feb 4, 2026
Medium6.5Linux

Medium [CVE-2026-25547] Denial of Service via unbounded brace range expansion

Denial of Service via unbounded brace range expansion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-409. Affected package(s): nodejs:22, nodejs22, nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-25547
Unclassified
Feb 4, 2026
Medium5.9Linux

Medium [CVE-2026-1642] Data injection via man-in-the-middle attack on TLS proxied connections

Data injection via man-in-the-middle attack on TLS proxied connections. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-349. Affected package(s): nginx-main, nginx, nginx:1.24, discovery/discovery-ui-rhel9:1773273070, nginx:1.26, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6408 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-1642
Unclassified
Feb 4, 2026
Medium6.5Linux

Medium [CVE-2026-23060] Linux kernel: Denial of Service in authencesn due to too-short AAD

Linux kernel: Denial of Service in authencesn due to too-short AAD. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1284. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:19074 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23060
Unclassified
Feb 4, 2026
High7.5Linux

High [CVE-2026-25223] Validation bypass due to malformed Content-Type header leading to integrity impact

Validation bypass due to malformed Content-Type header leading to integrity impact. Red Hat rates this important (CVSS 7.5). Weakness: CWE-179. Affected package(s): rhoai/odh-dashboard-rhel8:1774282136, rhoai/odh-mod-arch-model-registry-rhel9:1776742141, rhoai/odh-dashboard-rhel9:1776742021, devspaces/dashboard-rhel9:1774476526. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.16; Red Hat OpenShift AI 2.25; Red Hat OpenShift Dev Spaces 3.27; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more.

CVE-2026-25223
Red Hat Enterprise Linux
Feb 3, 2026
High7.5Vendor: MediumLinux

High [CVE-2025-14550] Denial of Service via crafted request with duplicate headers

Denial of Service via crafted request with duplicate headers. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-167. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, python-pulp-container. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2025-14550
Unclassified
Feb 3, 2026
High8.5Linux

High [CVE-2026-1312] SQL injection via crafted column aliases in QuerySet.order_by()

SQL injection via crafted column aliases in QuerySet.order_by(). Red Hat rates this important (CVSS 8.5). Weakness: CWE-89. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Satellite 6.16 for RHEL 8; and 5 more.

CVE-2026-1312
Red Hat Enterprise Linux
Feb 3, 2026
High8.3Linux

High [CVE-2026-1287] SQL Injection via crafted column aliases

SQL Injection via crafted column aliases. Red Hat rates this important (CVSS 8.3). Weakness: CWE-89. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Satellite 6.16 for RHEL 8; and 5 more.

CVE-2026-1287
Red Hat Enterprise Linux
Feb 3, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-1285] Denial of Service via crafted HTML inputs

Denial of Service via crafted HTML inputs. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, discovery/discovery-server-rhel9:1770913597, satellite/iop-advisor-backend-rhel9:1773451075, python-pulp-container. Resolved in Red Hat advisory RHSA-2026:3958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-1285
Unclassified
Feb 3, 2026