Complete feed
Security advisories & CVEs
5237 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-23957] Denial of Service via large encoded array lengths
Denial of Service via large encoded array lengths. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23956] Denial of Service via malicious regular expressions during deserialization
Denial of Service via malicious regular expressions during deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-71176] Denial of Service or Privilege Escalation via insecure temporary directory handling
Denial of Service or Privilege Escalation via insecure temporary directory handling. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-379. Affected package(s): pytest-main. Resolved in Red Hat advisory RHSA-2026:8580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-23893] Privilege Escalation or Data Exposure via Symlink Following
Privilege Escalation or Data Exposure via Symlink Following. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-59. Affected package(s): opencryptoki. Resolved in Red Hat advisory RHSA-2026:4717 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Critical [CVE-2026-24046] possible symlink path traversal in scaffolder actions
possible symlink path traversal in scaffolder actions. Red Hat rates this important (CVSS 9.1). Weakness: CWE-59. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
High [CVE-2026-23737] Arbitrary Code Execution via Improper JSON Deserialization
Arbitrary Code Execution via Improper JSON Deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23736] Prototype pollution via improper input validation during JSON deserialization
Prototype pollution via improper input validation during JSON deserialization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1321. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23960] Privilege escalation and information disclosure via stored Cross-Site Scripting (XSS)
Privilege escalation and information disclosure via stored Cross-Site Scripting (XSS). Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-22822] Cross-Namespace Secret Disclosure via `getSecretKey` Function
Cross-Namespace Secret Disclosure via `getSecretKey` Function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: external secrets operator for Red Hat OpenShift - Tech Preview.
High [CVE-2026-22807] Arbitrary code execution via untrusted model loading
Arbitrary code execution via untrusted model loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-gaudi-rhel9:1770956034. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 3 more.
High [CVE-2025-13465] prototype pollution in _.unset and _.omit functions
prototype pollution in _.unset and _.omit functions. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1321. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, openshift-gitops, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, openshift4/ose-console-rhel9:1770831186, multicluster-engine/console-mce-rhel9:1776223790. Resolved in Red Hat advisory RHSA-2026:3869 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Data Grid 8.6.0; Red Hat Enterprise Linux 10.0 Extended Update Support; and 77 more.
High [CVE-2025-13878] Denial of Service via corrupt or malicious record
Denial of Service via corrupt or malicious record. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Hardened Images.
Medium [CVE-2025-14559] Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users
Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-840. Affected package(s): keycloak-services, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-1035] Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition
Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition. Red Hat rates this low (CVSS 3.1). Weakness: CWE-367. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2025-15367] POP3 command injection in user-controlled commands
POP3 command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.
High [CVE-2025-15366] IMAP command injection in user-controlled commands
IMAP command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.
High [CVE-2026-21932] Enhance Handling of URIs (Oracle CPU 2026-01)
Enhance Handling of URIs (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.4). Weakness: CWE-1287. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0896 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.18; Red Hat Build of OpenJDK 21.0.10; Red Hat Build of OpenJDK 8u482.
High [CVE-2026-21945] Enhance Certificate Checking (Oracle CPU 2026-01)
Enhance Certificate Checking (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.18; Red Hat Build of OpenJDK 21.0.10; Red Hat Build of OpenJDK 25.0.2; Red Hat Build of OpenJDK 8u482; and 17 more.
High [CVE-2025-59465] Nodejs denial of service
Nodejs denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2025-55131] Nodejs uninitialized memory exposure
Nodejs uninitialized memory exposure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-497. Affected package(s): nodejs22, nodejs:20, nodejs:22, nodejs25-main, nodejs:24, nodejs24-main. Resolved in Red Hat advisory RHSA-2026:1842 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.