Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.9Red Hat

Medium [CVE-2026-55577] Heap buffer overflow in MVG decoder allows out-of-bounds write

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. This vulnerability could allow an attacker to cause an out-of-bounds write, potentially leading to a denial of service or other impacts. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55577
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-55510] Denial of Service via crafted 8BIM profile

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. This could lead to a denial of service, making the software unavailable. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55510
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-53467] Information disclosure vulnerability in MNG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. A flaw was found in ImageMagick. This flaw could allow an attacker to potentially access sensitive information from memory due to parts of image pixels being left unchanged during processing. This could lead to unauthorized disclosure of data. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-53467
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-13769] Information disclosure via overly permissive file permissions

Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws codeartifact login, aws iam create-virtual-mfa-device, aws deploy register). To remediate this issue, users should upgrade to AWS CLI 1.44.78 (v1) or 2.34.29 (v2) or later. This vulnerability can lead to information disclosure, potentially exposing sensitive user credentials to unauthorized local attackers. Successful exploitation requires an attacker to already have local access to the same Unix-like host as the targeted user. Additionally, the vulnerability relies on the system having an unrestricted umask configuration and requires the victim to manually execute specific AWS CLI subcommands (such as codeartifact login or iam create-virtual-mfa-device) that write credentials to the filesystem. Impact Limitations: The direct impact is strictly limited to localized information disclosure. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: awscli2.

CVE-2026-13769
Red Hat Enterprise Linux
Jul 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-53466] Denial of Service via integer overflow in XCF decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. An attacker could craft a malicious image file that, when processed by the XCF decoder, triggers an integer overflow. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-53466
Red Hat Enterprise Linux
Jul 1, 2026
Medium6.1Red Hat

Medium [CVE-2026-55628] Unauthorized file access due to missing policy checks in concatenate operation

In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26. A flaw was found in ImageMagick. The `-concatenate` operation, used for combining images, lacks proper security policy checks. This oversight could allow an attacker to read from or write to file paths that should otherwise be restricted by the security policy. This could lead to unauthorized access to sensitive system resources. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-1220. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55628
Red Hat Enterprise Linux
Jul 1, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-53489] Arbitrary host file read via symlink following in CRI checkpoint restore

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9. This vulnerability, categorized as a Path Traversal (CWE-61), allows an attacker to read arbitrary files on the host system by manipulating symlinked paths during the checkpoint restore process. This can lead to unauthorized information disclosure from the host. This vulnerability is not exploitable in several Red Hat products listed in the affect table. Although some shipped images include the containerd Go module (primarily v1.x, and in a few cases containerd v2.x API client libraries) as a build-time dependency for OCI image handling, they do not execute the containerd daemon or its CRI plugin. As a result, the vulnerable containerd CRI checkpoint-restore code path is not exercised. Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-59. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4.19; Red Hat Openshift Data Foundation 4.2; Exploit Intelligence; and 5 more.

CVE-2026-53489
Unclassified
Jul 1, 2026
Medium6.7Red Hat

Medium [CVE-2026-50195] Arbitrary code execution via CRI checkpoint image tag poisoning

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknowingly execute the attacker's malicious image instead of the legitimate one. This can lead to a compromise of the affected pods, allowing the attacker to execute arbitrary code under the victim pod's identity. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9. Red Hat products include the containerd Go module (v1.x) as a library dependency. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-1289. Affected Red Hat products: Red Hat Hardened Images.

CVE-2026-50195
Unclassified
Jul 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-47262] Denial of Service via maliciously crafted image leading to unbounded group parsing

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2. A remote attacker could exploit this vulnerability by providing a maliciously crafted image. When a container is created from this image, it leads to uncontrolled resource consumption and memory exhaustion, causing the containerd process to terminate. While containerd libraries are bundled in some images for OCI image operations (e.g., estargz support via skopeo), the containerd daemon and its CRI plugin (where the vulnerable group-parsing code path exists) are not executed. Therefore, this vulnerability is not exploitable in Red Hat products. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images.

CVE-2026-47262
Unclassified
Jul 1, 2026
Medium4.4Red Hat

Medium [CVE-2026-5051] Audit device validation bypass via legacy file audit path option

HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17. This inconsistency could allow an attacker to bypass security controls, potentially leading to unauthorized access to sensitive information. Red Hat products that bundle the Vault Go client library (github.com/hashicorp/vault/api) are not affected because they only use the client SDK to connect to external Vault servers for secrets/KMS operations. The vulnerable code is in the Vault server's audit subsystem (vault/audit, vault/vault, vault/builtin packages), which is not imported or executed by any Red Hat product. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-807. Red Hat lists Red Hat OpenShift Container Platform 4; Red Hat Openshift Data Foundation 4 as not affected.

CVE-2026-5051
Unclassified
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-12480] Information disclosure via malicious model archive with Virtual Dataset

Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1. A flaw was found in Keras. This vulnerability leads to information disclosure, allowing an attacker to access sensitive data from the victim's filesystem. Moderate: This information disclosure flaw in Keras affects Red Hat OpenShift AI components that utilize Keras. Exploitation requires user interaction, specifically loading an untrusted model, which limits the attack vector to scenarios where users process external, potentially malicious, model files. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12480
Unclassified
Jul 1, 2026
Medium4.6Red Hat

Medium [CVE-2026-58031] Cross-site scripting vulnerability due to improper input neutralization

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki. Special. Apisandbox/ApiSandboxLayout.Js. This issue affects MediaWiki: from 1.46.0-rc.0 before 1.46.0. When a user views an affected page, the attacker's script can execute in their browser, potentially leading to information disclosure, session hijacking, or defacement of the website. Moderate: A cross-site scripting (XSS) vulnerability in MediaWiki allows a remote attacker to inject malicious scripts into web pages. Red Hat severity: Moderate — CVSS 4.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-79.

CVE-2026-58031
Unclassified
Jul 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-5138] Information disclosure via improper validation of nested request parameters

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-639. Affected Red Hat products: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; Red Hat Satellite 6.19 for RHEL 9; Red Hat Satellite 6. Red Hat fixing advisory: RHSA-2026:34367, RHSA-2026:34366, RHSA-2026:34368, RHSA-2026:34365.

CVE-2026-5138
Unclassified
Jul 1, 2026
Medium5.4Red Hat

Medium [CVE-2026-13323] Supply chain attack via cross-site scripting

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension versions. Because Open VSX extensions are distributed to VS Code, VSCodium, Cursor, Windsurf, and compatible editors, a compromised extension update constitutes a supply chain attack against all downstream users. This Moderate flaw in Open VSX Registry, as utilized by Red Hat OpenShift Dev Spaces, involves a cross-site scripting vulnerability. An attacker with a registered publisher account could upload a crafted extension, and if an authenticated user is enticed to visit a specific URL, their session tokens could be exfiltrated, or unauthorized extension publications could occur. This requires both attacker prerequisites and user interaction, which limits the overall impact. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-79.

CVE-2026-13323
Unclassified
Jul 1, 2026
Medium6.1Red Hat

Medium [CVE-2025-15666] Heap-based buffer overflow via crafted model file

A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::SceneCombiner::Copy of the file code/Common/SceneCombiner.cpp of the component Model File Handler. Such manipulation of the argument width/height leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128. A local attacker could exploit a vulnerability where specially crafted model files could cause a heap-based buffer overflow. This issue, occurring in the `SceneCombiner::Copy` function, could allow an attacker to gain unauthorized access to sensitive information or cause the application to crash, leading to a denial of service. Successful exploitation requires local access and user interaction. An attacker must supply a specially crafted model file and rely on a user or an application to actively process it using the Assimp library. The impact of this vulnerability is localized specifically to the application parsing the malformed file. While it can lead to an application crash (Denial of Service) or localized information disclosure, it does not allow for privilege escalation, remote code execution, or a broader system-wide compromise.

CVE-2025-15666
Red Hat Enterprise Linux
Jul 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-14324] RAOP RTSP NULL Deref

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Under investigation: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-14324
Unclassified
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-14330] Pulse Server alloca Stack Overflow

Multiple unbounded alloca() calls in the PulseAudio protocol server. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Under investigation: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-14330
Unclassified
Jul 1, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-53333] handle non-swap entries before !CONFIG_SWAP guard

In the Linux kernel, the following vulnerability has been resolved: mm/mincore: handle non-swap entries before!CONFIG_SWAP guard mincore_swap() also fields migration/hwpoison entries (and shmem swapin-error entries), which can exist on!CONFIG_SWAP builds when CONFIG_MIGRATION or CONFIG_MEMORY_FAILURE is enabled. The!IS_ENABLED(CONFIG_SWAP) guard ran before the non-swap-entry early return, so mincore_pte_range() can spuriously WARN and report these pages nonresident on!CONFIG_SWAP kernels. Move the guard below the non-swap-entry check so only true swap entries trip the WARN, and migration/hwpoison entries take the existing "uptodate / non-shmem" path. A flaw was found in the Linux kernel's memory management (mm/mincore). This vulnerability occurs when handling non-swap memory entries, particularly in systems configured without swap. An issue in the `mincore_pte_range()` function can cause the system to incorrectly report certain memory pages as nonresident, leading to spurious warnings. This could potentially impact system stability or lead to misdiagnosis of memory conditions. Red Hat severity: Low — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-393. Affected Red Hat products: Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-53333
Linux Kernel
Jul 1, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-53353] Remove WARN_ONCE in hsr_addr_is_self

In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0] in hsr_addr_is_self(), whose assumption is simply wrong. hsr->self_node is cleared in hsr_del_self_node(), which is called from hsr_dellink(). Since dev->rtnl_link_ops->dellink() is called before unregister_netdevice_many(), there is a window when user can find the device but without hsr->self_node. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-53353
Linux Kernel
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-53349] destroy stale expectfn expectations on unregister

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT helpers such as nf_nat_h323 store a raw pointer to module text in exp->expectfn (e.g. ip_nat_q931_expect). nf_ct_helper_expectfn_unregister() only unlinks the callback descriptor and never walks the expectation table, so an expectation pending at module removal survives with a dangling exp->expectfn into freed module text. When the expected connection arrives, init_conntrack() invokes exp->expectfn(), now a stale pointer into the unloaded module. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.

CVE-2026-53349
Linux Kernel
Jul 1, 2026