Complete feed
Security advisories & CVEs
5209 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-24842] Arbitrary file creation via path traversal bypass in hardlink security check
Arbitrary file creation via path traversal bypass in hardlink security check. Red Hat rates this important (CVSS 8.2). Weakness: CWE-59. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, network-observability/network-observability-console-plugin-compat-rhel9:1771227610, eap7-wildfly, rhtas/rekor-search-ui-rhel9:1773308315, linux-sgx, devspaces/dashboard-rhel9:1774476526. Resolved in Red Hat advisory RHSA-2026:18868 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat OpenShift Dev Spaces 3.27; and 7 more.
High [CVE-2025-57283] OS command injection in the logfile variable in lib/Local.js
OS command injection in the logfile variable in lib/Local.js. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2025-61140] Prototype Pollution vulnerability in the value function
Prototype Pollution vulnerability in the value function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): ansible-automation-platform/automation-portal:1770282458, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647, ansible-automation-platform/automation-portal:1770281704. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.8; and 4 more.
Medium [CVE-2025-61730] Handshake messages may be processed at the incorrect encryption level in crypto/tls
Handshake messages may be processed at the incorrect encryption level in crypto/tls. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-325. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-68119] Local code execution and arbitrary file write via malicious module version strings
Local code execution and arbitrary file write via malicious module version strings. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-15467] Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. Affected package(s): service-interconnect/skupper-operator-bundle:1.8.8, devspaces/dashboard-rhel9:1770764461, devspaces/pluginregistry-rhel9:1770918006, service-interconnect/skupper-controller-podman-container-rhel9:1.8.8, rhui5/rhua-rhel9:1773670137, openssl. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; and 32 more.
Critical [CVE-2026-24480] QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration
QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration. Red Hat rates this important (CVSS 9.9). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-24779] Server-Side Request Forgery allows internal network access
Server-Side Request Forgery allows internal network access. Red Hat rates this important (CVSS 7.1). Weakness: CWE-918. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 2 more.
High [CVE-2026-24765] Arbitrary code execution via unsafe deserialization of code coverage files
Arbitrary code execution via unsafe deserialization of code coverage files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-24747] Arbitrary code execution via malicious checkpoint file loading
Arbitrary code execution via malicious checkpoint file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.
High [CVE-2026-24882] Stack-based buffer overflow in tpm2daemon allows arbitrary code execution
Stack-based buffer overflow in tpm2daemon allows arbitrary code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-121. Affected package(s): gnupg2. Resolved in Red Hat advisory RHSA-2026:2753 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.
High [CVE-2026-24881] Remote code execution and denial of service via crafted CMS EnvelopedData message
Remote code execution and denial of service via crafted CMS EnvelopedData message. Red Hat rates this important (CVSS 8.1). Weakness: CWE-121. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.
High [CVE-2026-24869] Use-after-free in the Layout: Scrolling and Overflow component
Use-after-free in the Layout: Scrolling and Overflow component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-21721] Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation
Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. Affected package(s): grafana, rhacm2/acm-grafana-rhel9:1774950654, rhacm2/acm-grafana-rhel9:1774002166. Resolved in Red Hat advisory RHSA-2026:2920 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Advanced Cluster Management for Kubernetes 2.12; Red Hat Advanced Cluster Management for Kubernetes 2.13; and 4 more.
High [CVE-2026-21720] Denial of Service via resource exhaustion from avatar requests
Denial of Service via resource exhaustion from avatar requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-24486] Arbitrary file write via path traversal vulnerability
Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363, rhoai/odh-vllm-gaudi-rhel9:1770956034, rhaiis/vllm-cuda-rhel9:1772160593, rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: python-multipart; Red Hat AI Inference Server 3.2; Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; and 6 more.
High [CVE-2025-69419] Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
Arbitrary code execution due to out-of-bounds write in PKCS#12 processing. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-131. Affected package(s): jbcs-httpd24-mod_md, rhcos, jbcs-httpd24-mod_http2, rhui5/installer-rhel9:1770646925, jbcs-httpd24-mod_proxy_cluster, openssl-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2025-11187] Arbitrary code execution or denial of service through crafted PKCS#12 file
Arbitrary code execution or denial of service through crafted PKCS#12 file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-233. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-15468] Denial of Service via NULL pointer dereference in QUIC protocol handling
Denial of Service via NULL pointer dereference in QUIC protocol handling. Red Hat rates this low (CVSS 5.9). Weakness: CWE-476. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-15469] Data integrity bypass in `openssl dgst` command due to silent truncation
Data integrity bypass in `openssl dgst` command due to silent truncation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.