Complete feed
Security advisories & CVEs
3463 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue
Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator
FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.
High [CVE-2026-45774] Arbitrary file read via path traversal in profile import
Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism
Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-48099] Filesystem path traversal via encoded dot segments
Filesystem path traversal via encoded dot segments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22.
High [CVE-2026-73643] Denial of Service via exponential parsing in flow collections
Denial of Service via exponential parsing in flow collections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 31 more. Affected products named by the advisory: Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; and 27 more.
High [CVE-2026-73569] Denial of Service via repeated DOCTYPE declarations
Denial of Service via repeated DOCTYPE declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat Advanced Cluster Security 4; Red Hat Openshift Data Foundation 4; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenShift Virtualization 4; Self-service automation portal 2.
High [CVE-2026-73566] Denial of Service via crafted long-path tar archive
Denial of Service via crafted long-path tar archive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Migration Toolkit for Containers; Node HealthCheck Operator; and 30 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; and 26 more.
High [CVE-2026-58440] Information disclosure via incomplete webhook revocation
Information disclosure via incomplete webhook revocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-459. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-58439] Branch protection bypass via stale approval flag in PR retargeting
Branch protection bypass via stale approval flag in PR retargeting. Red Hat rates this important (CVSS 7.7). Weakness: CWE-472.
High [CVE-2026-58436] Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests
Denial of Service via ParseAcceptLanguage and Locale middleware on unauthenticated requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333.
High [CVE-2026-58437] Repository visibility manipulation via Git push options
Repository visibility manipulation via Git push options. Red Hat rates this important (CVSS 7.1). Weakness: CWE-1220. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-58314] Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery
Server-Side Request Forgery via webhooks, repository migration, and OpenID discovery. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-56750] Unauthorized access due to remember-me token theft not invalidating attacker sessions.
Unauthorized access due to remember-me token theft not invalidating attacker sessions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-613. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-56654] Privilege Escalation via API Access Token Scope Escalation
Privilege Escalation via API Access Token Scope Escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266.
High [CVE-2026-54481] Insecure TLS verification in internal API client
Insecure TLS verification in internal API client. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Affected product named by the advisory: OpenShift Pipelines.
High [CVE-2026-73515] Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer
Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql16-postgis; Red Hat package: postgresql18-postgis.
High [CVE-2026-73556] Denial of Service via Regular Expression processing
Denial of Service via Regular Expression processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-70452] rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure. Red Hat rates this important (CVSS 7.4). Weakness: CWE-636. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.