Complete feed
Security advisories & CVEs
3284 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2022-50999] Integer overflow in libxml2 leads to information disclosure, data modification, or denial of service
Integer overflow in libxml2 leads to information disclosure, data modification, or denial of service. Red Hat rates this important (CVSS 8.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
High [CVE-2021-47996] Memory Corruption via Crafted XML Documents
Memory Corruption via Crafted XML Documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
High [CVE-2022-50998] Denial of Service and Memory Corruption via Crafted XML Input
Denial of Service and Memory Corruption via Crafted XML Input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
High [CVE-2026-2035364] Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints
Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
High [CVE-2026-2035366] Application credential tokens can escape project scope via token-method reauthentication
Application credential tokens can escape project scope via token-method reauthentication. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863.
High [CVE-2026-78360] missing authorization check in delete_user allows any authenticated user to delete arbitrary users
missing authorization check in delete_user allows any authenticated user to delete arbitrary users. Red Hat rates this important (CVSS 7.1). Weakness: CWE-862.
High [CVE-2026-79655] path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sos.
High [CVE-2026-18798] QUIC server may trigger double free when processing INITIAL packet
QUIC server may trigger double free when processing INITIAL packet. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-415. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat OpenShift Container Platform 4; and 2 more.
High [CVE-2026-63072] heap buffer overflow in CMS key unwrapping
heap buffer overflow in CMS key unwrapping. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; and 12 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; and 8 more.
High [CVE-2026-63076] invalid pointer dereference in CMP server via crafted protectionAlg
invalid pointer dereference in CMP server via crafted protectionAlg. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 8 more. Affected products named by the advisory: Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat OpenShift Container Platform 4; and 4 more.
High [CVE-2026-14457] RPK server signature algorithm selection can dereference a missing certificate
RPK server signature algorithm selection can dereference a missing certificate. Red Hat rates this low (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat OpenShift Container Platform 4; and 2 more.
High [CVE-2026-54874] excessive memory use buffering DTLS records for a future epoch
excessive memory use buffering DTLS records for a future epoch. Red Hat rates this low (CVSS 7.5). Weakness: CWE-405. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; and 18 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Core Services; and 14 more.
High [CVE-2026-63074] CMP indefinite cache growth of ExtraCerts
CMP indefinite cache growth of ExtraCerts. Red Hat rates this low (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59641 with package openssl3-main-3.5.8-0.1.hum1, openssl-main-3.5.8-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 8 more. Affected products named by the advisory: Red Hat JBoss Core Services; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat OpenShift Container Platform 4; and 4 more.
High [CVE-2026-52491] Arbitrary code execution via thumbnail.c: main component
Arbitrary code execution via thumbnail.c: main() component. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53467 with package libtiff-main-4.7.2-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: libtiff; Red Hat package: compat-libtiff3; and 1 more.
High [CVE-2026-76098] Denial of Service via excessive emphasis markers in Markdown
Denial of Service via excessive emphasis markers in Markdown. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.
High [CVE-2026-78465] Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when the plugin subsequently writes image data into the undersized buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PCX image with GIMP, reducing the likelihood of exploitation. However, successful exploitation may potentially lead to arbitrary code execution or a denial of service. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to this reason, this flaw has been rated with an important severity. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
High [CVE-2025-9615 +1] 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing WPA-Enterprise server validation bypass (incomplete fix for CVE-2025-9615)
802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing WPA-Enterprise server validation bypass (incomplete fix for CVE-2025-9615). Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: networkmanager.
High [CVE-2026-71366] notification backends allow SSRF and credential leakage
notification backends allow SSRF and credential leakage. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59153 with package automation-controller-0:4.7.16-1.el9ap, ansible-automation-platform-26/controller-rhel9:1787244009, automation-controller-0:4.6.32-1.el8ap, ansible-automation-platform-27/controller-rhel9:1787220257. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-71364] project archive extraction allows path traversal file writes
project archive extraction allows path traversal file writes. Red Hat rates this important (CVSS 7.2). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:59153 with package automation-controller-0:4.7.16-1.el9ap, ansible-automation-platform-26/controller-rhel9:1787244009, automation-controller-0:4.6.32-1.el8ap, ansible-automation-platform-27/controller-rhel9:1787220257. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-78367] rpmbuild getTarSpec crafted tar member name → macro injection
rpmbuild getTarSpec() crafted tar member name → macro injection. Red Hat rates this moderate (CVSS 7). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.