Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5233 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Linux

High [CVE-2025-61726] Memory exhaustion in query parameter parsing in net/url

Memory exhaustion in query parameter parsing in net/url. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-multus-route-override-cni-rhel8:1777001628, openshift4/ose-tests:1777002345, skopeo, openshift4/ose-hypershift-rhel8:1777001784. Resolved in Red Hat advisory RHSA-2026:11749 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 8; and 138 more.

CVE-2025-61726
Red Hat Enterprise Linux
Jan 28, 2026
High8.6Linux

High [CVE-2025-61731] Arbitrary file write via malicious pkg-config directive

Arbitrary file write via malicious pkg-config directive. Red Hat rates this important (CVSS 8.6). Weakness: CWE-88. Affected package(s): openshift4/ose-csi-livenessprobe-rhel8:1776999947, openshift4/ose-csi-external-snapshotter-rhel8:1776999951, openshift4/ose-prometheus-node-exporter-rhel9:1774294099, openshift4/oc-mirror-plugin-rhel9:1776961082, openshift4/ose-azure-file-csi-driver-operator-rhel9:1773363768, openshift4/ose-multus-route-override-cni-rhel8:1777001628. Resolved in Red Hat advisory RHSA-2026:5948 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 24 more.

CVE-2025-61731
Red Hat Enterprise Linux
Jan 28, 2026
High8.1Linux

High [CVE-2026-1530] Man-in-the-Middle vulnerability due to disabled certificate validation

Man-in-the-Middle vulnerability due to disabled certificate validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Affected package(s): foreman, rubygem-katello, rubygem-fog-kubevirt, python-pulp-container, python-pulp-rpm, python-django. Resolved in Red Hat advisory RHSA-2026:5971 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9.

CVE-2026-1530
Red Hat Enterprise Linux
Jan 28, 2026
High8.1Linux

High [CVE-2026-1531] Man-in-the-Middle due to insecure default SSL verification

Man-in-the-Middle due to insecure default SSL verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Affected package(s): foreman, rubygem-katello, rubygem-foreman_kubevirt, rubygem-fog-kubevirt, python-pulp-container, python-pulp-rpm. Resolved in Red Hat advisory RHSA-2026:5968 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9.

CVE-2026-1531
Red Hat Enterprise Linux
Jan 28, 2026
High8.2Linux

High [CVE-2026-24842] Arbitrary file creation via path traversal bypass in hardlink security check

Arbitrary file creation via path traversal bypass in hardlink security check. Red Hat rates this important (CVSS 8.2). Weakness: CWE-59. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, network-observability/network-observability-console-plugin-compat-rhel9:1771227610, eap7-wildfly, rhtas/rekor-search-ui-rhel9:1773308315, linux-sgx, devspaces/dashboard-rhel9:1774476526. Resolved in Red Hat advisory RHSA-2026:18868 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat OpenShift Dev Spaces 3.27; and 7 more.

CVE-2026-24842
Red Hat Enterprise Linux
Jan 28, 2026
High7.8Linux

High [CVE-2025-57283] OS command injection in the logfile variable in lib/Local.js

OS command injection in the logfile variable in lib/Local.js. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2025-57283
Unclassified
Jan 28, 2026
High8.8Linux

High [CVE-2025-61140] Prototype Pollution vulnerability in the value function

Prototype Pollution vulnerability in the value function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): ansible-automation-platform/automation-portal:1770282458, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647, ansible-automation-platform/automation-portal:1770281704. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.8; and 4 more.

CVE-2025-61140
Red Hat Enterprise Linux
Jan 28, 2026
Medium5.3Linux

Medium [CVE-2025-61730] Handshake messages may be processed at the incorrect encryption level in crypto/tls

Handshake messages may be processed at the incorrect encryption level in crypto/tls. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-325. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-61730
Unclassified
Jan 28, 2026
Medium6.7Linux

Medium [CVE-2025-68119] Local code execution and arbitrary file write via malicious module version strings

Local code execution and arbitrary file write via malicious module version strings. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-68119
Unclassified
Jan 28, 2026
Critical9.8Vendor: HighLinux

Critical [CVE-2025-15467] Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. Affected package(s): service-interconnect/skupper-operator-bundle:1.8.8, devspaces/dashboard-rhel9:1770764461, devspaces/pluginregistry-rhel9:1770918006, service-interconnect/skupper-controller-podman-container-rhel9:1.8.8, rhui5/rhua-rhel9:1773670137, openssl. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; and 32 more.

CVE-2025-15467
Red Hat Enterprise Linux
Jan 27, 2026
Critical9.9Vendor: HighLinux

Critical [CVE-2026-24480] QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration

QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration. Red Hat rates this important (CVSS 9.9). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24480
Unclassified
Jan 27, 2026
High7.1Linux

High [CVE-2026-24779] Server-Side Request Forgery allows internal network access

Server-Side Request Forgery allows internal network access. Red Hat rates this important (CVSS 7.1). Weakness: CWE-918. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 2 more.

CVE-2026-24779
Red Hat Enterprise Linux
Jan 27, 2026
High7.8Linux

High [CVE-2026-24765] Arbitrary code execution via unsafe deserialization of code coverage files

Arbitrary code execution via unsafe deserialization of code coverage files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24765
Unclassified
Jan 27, 2026
High8.8Linux

High [CVE-2026-24747] Arbitrary code execution via malicious checkpoint file loading

Arbitrary code execution via malicious checkpoint file loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.

CVE-2026-24747
Unclassified
Jan 27, 2026
High8.4Linux

High [CVE-2026-24882] Stack-based buffer overflow in tpm2daemon allows arbitrary code execution

Stack-based buffer overflow in tpm2daemon allows arbitrary code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-121. Affected package(s): gnupg2. Resolved in Red Hat advisory RHSA-2026:2753 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-24882
Red Hat Enterprise Linux
Jan 27, 2026
High8.1Linux

High [CVE-2026-24881] Remote code execution and denial of service via crafted CMS EnvelopedData message

Remote code execution and denial of service via crafted CMS EnvelopedData message. Red Hat rates this important (CVSS 8.1). Weakness: CWE-121. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 6.

CVE-2026-24881
Red Hat Enterprise Linux
Jan 27, 2026
High7.5Linux

High [CVE-2026-24869] Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24869
Unclassified
Jan 27, 2026
High8.1Linux

High [CVE-2026-21721] Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation

Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. Affected package(s): grafana, rhacm2/acm-grafana-rhel9:1774950654, rhacm2/acm-grafana-rhel9:1774002166. Resolved in Red Hat advisory RHSA-2026:2920 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Advanced Cluster Management for Kubernetes 2.12; Red Hat Advanced Cluster Management for Kubernetes 2.13; and 4 more.

CVE-2026-21721
Red Hat Enterprise Linux
Jan 27, 2026
High7.5Linux

High [CVE-2026-21720] Denial of Service via resource exhaustion from avatar requests

Denial of Service via resource exhaustion from avatar requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-21720
Unclassified
Jan 27, 2026
High8.6Linux

High [CVE-2026-24486] Arbitrary file write via path traversal vulnerability

Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-cpu-rhel9:1778264363, rhoai/odh-vllm-gaudi-rhel9:1770956034, rhaiis/vllm-cuda-rhel9:1772160593, rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: python-multipart; Red Hat AI Inference Server 3.2; Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 2.25; and 6 more.

CVE-2026-24486
Red Hat Enterprise Linux
Jan 27, 2026