Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism
Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-48099] Filesystem path traversal via encoded dot segments
Filesystem path traversal via encoded dot segments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22.
High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections
Denial of Service via exponential parsing in flow collections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 31 more. Affected products named by the advisory: Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; and 27 more.
High [CVE-2026-73569] Denial of Service via repeated DOCTYPE declarations
Denial of Service via repeated DOCTYPE declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat Advanced Cluster Security 4; Red Hat Openshift Data Foundation 4; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenShift Virtualization 4; Self-service automation portal 2.
High [CVE-2026-73566] Denial of Service via crafted long-path tar archive
Denial of Service via crafted long-path tar archive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Migration Toolkit for Containers; Node HealthCheck Operator; and 30 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; and 26 more.
High [CVE-2026-58440] Information disclosure via incomplete webhook revocation
Information disclosure via incomplete webhook revocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-58439] Branch protection bypass via stale approval flag in PR retargeting
Branch protection bypass via stale approval flag in PR retargeting. Red Hat rates this important (CVSS 7.7). Weakness: CWE-472.
High [CVE-2026-58436] Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests
Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333.
High [CVE-2026-58437] Repository visibility manipulation via Git push options
Repository visibility manipulation via Git push options. Red Hat rates this important (CVSS 7.1). Weakness: CWE-1220. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-58314] Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery
Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-56750] Unauthorized access due to remember-me token theft not invalidating attacker sessions.
Unauthorized access due to remember-me token theft not invalidating attacker sessions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-613. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-56654] Privilege Escalation via API Access Token Scope Escalation
Privilege Escalation via API Access Token Scope Escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266.
High [CVE-2026-54481] Insecure TLS verification in internal API client
Insecure TLS verification in internal API client. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-73515] Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer
Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql16-postgis; Red Hat package: postgresql18-postgis.
High [CVE-2026-73556] Denial of Service via Regular Expression processing
Denial of Service via Regular Expression processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-70452] rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-636. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70455] Denial of Service via Zstandard compression thread exhaustion
Denial of Service via Zstandard compression thread exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: rsync.
High [CVE-2026-70456] Heap Out-of-Bounds Write via crafted argument list
Heap Out-of-Bounds Write via crafted argument list. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70458] Memory corruption via crafted file entries
Memory corruption via crafted file entries. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70460] rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.