Complete feed
Security advisories & CVEs
5243 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-1145] quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service
quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service. Red Hat rates this important (CVSS 6.3). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1144] Use-after-free vulnerability in Atomics Ops Handler
Use-after-free vulnerability in Atomics Ops Handler. Red Hat rates this important (CVSS 6.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1180] Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri
Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-918. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-1190] Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData
Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData. Red Hat rates this low (CVSS 3.1). Weakness: CWE-112. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23745] Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives
Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, devspaces/udi-rhel9:1774451954, rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056, rhoai/odh-dashboard-rhel9:1779189627, linux-sgx. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 19 more.
High [CVE-2021-47839] Remote Code Execution via persistent cross-site scripting
Remote Code Execution via persistent cross-site scripting. Red Hat rates this important. Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23490] Denial of Service due to memory exhaustion from malformed RELATIVE-OID
Denial of Service due to memory exhaustion from malformed RELATIVE-OID. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): python-pyasn1, ansible-automation-platform, fence-agents, rhelai3/bootc-azure-rocm-rhel9:1778677745, resource-agents, automation-controller. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; and 34 more.
High [CVE-2025-62291] Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message
Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message. Red Hat rates this important (CVSS 8.1). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23527] HTTP Request Smuggling due to improper case-sensitive parsing of Transfer-Encoding header
HTTP Request Smuggling due to improper case-sensitive parsing of Transfer-Encoding header. Red Hat rates this important (CVSS 8.9). Weakness: CWE-444. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-22775] Denial of Service due to improper input validation
Denial of Service due to improper input validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-405. Affected package(s): rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056. Resolved in Red Hat advisory RHSA-2026:2926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Trusted Artifact Signer 1.2; Red Hat Trusted Artifact Signer 1.3; Red Hat Build of Podman Desktop - Tech Preview.
High [CVE-2026-22774] Denial of Service due to excessive resource consumption from untrusted input
Denial of Service due to excessive resource consumption from untrusted input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-405. Affected package(s): rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056. Resolved in Red Hat advisory RHSA-2026:2926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Trusted Artifact Signer 1.2; Red Hat Trusted Artifact Signer 1.3; Red Hat Build of Podman Desktop - Tech Preview.
High [CVE-2026-0897] Denial of Service via crafted HDF5 weight loading file
Denial of Service via crafted HDF5 weight loading file. Red Hat rates this important (CVSS 7.6). Weakness: CWE-770. Affected package(s): rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1772093304, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1772093283, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1772093300, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1771502844, rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1771502884, rhoai/odh-modelmesh-runtime-adapter-rhel9:1772094445. Resolved in Red Hat advisory RHSA-2026:4271 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat Trusted Artifact Signer 1.3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-22045] Denial of Service via ACME TLS-ALPN fast path resource exhaustion
Denial of Service via ACME TLS-ALPN fast path resource exhaustion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected package(s): devspaces/traefik-rhel9:1774227265. Resolved in Red Hat advisory RHSA-2026:6192 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-0915] Information disclosure via zero-valued network query
Information disclosure via zero-valued network query. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-908. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137, glibc, discovery/discovery-server-rhel9:1773273243, discovery/discovery-ui-rhel9:1773273070, glibc-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-1002] static handler component cache can be manipulated to deny the access to static files
static handler component cache can be manipulated to deny the access to static files. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected package(s): rhoai/odh-trustyai-service-rhel9:1776748859, eap7-wildfly, vertx-core, cryostat/jfr-datasource-rhel9:4.2.0, vertx-core-logging, devspaces/server-rhel9:1774228740. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7.
Medium [CVE-2026-0990] Denial of Service via uncontrolled recursion in XML catalog processing
Denial of Service via uncontrolled recursion in XML catalog processing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-674. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0988] Denial of Service via Integer Overflow in g_buffered_input_stream_peek()
Denial of Service via Integer Overflow in g_buffered_input_stream_peek(). Red Hat rates this low (CVSS 3.7). Weakness: CWE-190. Affected package(s): glib2-main. Resolved in Red Hat advisory RHSA-2026:7461 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0989] Unbounded RelaxNG Include Recursion Leading to Stack Overflow
Unbounded RelaxNG Include Recursion Leading to Stack Overflow. Red Hat rates this low (CVSS 3.7). Weakness: CWE-674. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-0992] Denial of Service via crafted XML catalogs
Denial of Service via crafted XML catalogs. Red Hat rates this low (CVSS 2.9). Weakness: CWE-400. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-70968] Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE()
Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE(). Red Hat rates this important (CVSS 9.8). Weakness: CWE-416. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.