Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8Red Hat

High [CVE-2026-28984] Processing maliciously crafted web content may lead to an unexpected Safari crash

Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:25918 with package webkit2gtk3-0:2.52.4-1.el8_8, webkit2gtk3-0:2.52.4-1.el9_8, webkit2gtk3-0:2.52.4-1.el8_4, webkit2gtk3-0:2.52.4-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-28984
Unclassified
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-64719] Processing maliciously crafted web content may lead to an unexpected Safari crash

Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120.

CVE-2026-64719
Unclassified
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-64787] Processing maliciously crafted web content may lead to an unexpected process termination

Processing maliciously crafted web content may lead to an unexpected process termination. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_2, webkit2gtk3-0:2.52.5-1.el8_4, webkit2gtk3-0:2.52.5-1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-64787
Unclassified
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-64757] Processing maliciously crafted web content may lead to an unexpected Safari crash

Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64757
Red Hat Enterprise Linux
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-64783] Processing maliciously crafted web content may lead to an unexpected Safari crash

Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64783
Red Hat Enterprise Linux
Aug 20, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-55894] Denial of Service via crafted SH2A bytecode

Denial of Service via crafted SH2A bytecode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-55894
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.4Red Hat Updated

Medium [CVE-2026-77643] Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping

Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: xapian-core.

CVE-2026-77643
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-53586] Information disclosure via HTTP redirect allows credential leakage

Information disclosure via HTTP redirect allows credential leakage. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53586
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-53583] Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison

Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53583
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-53585] Denial of Service via Unbounded Memory Allocation

Denial of Service via Unbounded Memory Allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53585
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-63379] HTTP header smuggling allows authorization bypass or cache poisoning

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. An unauthenticated remote attacker can exploit a vulnerability where chunked HTTP (Hypertext Transfer Protocol) trailers are incorrectly merged into request headers. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:60853. Affected products named by the advisory: Red Hat package: libevent2.

CVE-2026-63379
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.7Red Hat Updated

Medium [CVE-2026-63380] Denial of Service via Null Pointer Dereference

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha. This vulnerability allows a local attacker to trigger a null pointer dereference during specific error handling within the `evws_new_session` function. By inducing an allocation or locking failure, an attacker can cause the application to crash, leading to a denial of service. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libevent2.

CVE-2026-63380
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.6Red Hat Updated

Medium [CVE-2026-63381] Memory corruption due to use-after-free

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This can lead to a dangling pointer, which an attacker could exploit to cause memory corruption or crash the application. Red Hat severity: Moderate — CVSS 6.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:60853. Affected products named by the advisory: Red Hat package: libevent2.

CVE-2026-63381
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-71492] Arbitrary file write via path traversal

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation. Relative traversal such as../victim/foo and an absolute Prompt.name can escape or discard the configured registry root, while overwrite=True permits replacement of existing target files. The poisoned name is persisted in index.json and reconstructed by _load(), allowing the out-of-root path to survive later registry loads. An application that forwards request data into these fields can therefore write Prompt.raw bytes to attacker-chosen paths writable by the application process. This issue is fixed in version 2.4.5. A flaw was found in Banks. This allows for path traversal, enabling an attacker to write arbitrary files outside the intended registry root. This vulnerability could lead to unauthorized modification of files on the system where Banks is running. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-22.

CVE-2026-71492
Unclassified
Aug 20, 2026
Medium5.4Apache

Medium [CVE-2026-63044] Server-Side Request Forgery (SSRF) vulnerability in Apache InLong

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63044
Unclassified
Aug 20, 2026
Medium5.3Apache

Medium [CVE-2026-63016] Uncontrolled Resource Consumption vulnerability in Apache InLong

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]

CVE-2026-63016
Unclassified
Aug 20, 2026
Medium4.3Apache

Medium [CVE-2026-63015] Uncontrolled Resource Consumption vulnerability in Apache InLong

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]

CVE-2026-63015
Unclassified
Aug 20, 2026
Medium6.5Red Hat

Medium [CVE-2026-73199] NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value

NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.

CVE-2026-73199
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.3Red Hat

Medium [CVE-2026-73196] Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding

Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.

CVE-2026-73196
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.9Red Hat Updated

Medium [CVE-2026-76957] Memory corruption vulnerability allows arbitrary code execution or denial of service

Memory corruption vulnerability allows arbitrary code execution or denial of service. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: expat; and 5 more.

CVE-2026-76957
Red Hat Enterprise Linux
Aug 20, 2026