Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8Red Hat Updated

High [CVE-2026-70495] cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters

cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters. Red Hat rates this important (CVSS 8.8). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-70495
Unclassified
Aug 17, 2026
High8.4Red Hat Updated

High [CVE-2026-46345] Arbitrary file write via path traversal vulnerability

Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.

CVE-2026-46345
Unclassified
Aug 17, 2026
High7.5Red Hat Updated

High [CVE-2026-54284] Denial of Service via quadratic CPU consumption in SQL parsing

Denial of Service via quadratic CPU consumption in SQL parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 7 more. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; and 3 more.

CVE-2026-54284
Unclassified
Aug 17, 2026
High7.5Red Hat Updated

High [CVE-2026-59893] Denial of Service via inefficient SQL parsing

Denial of Service via inefficient SQL parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 7 more. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; and 3 more.

CVE-2026-59893
Unclassified
Aug 17, 2026
High7.5Red Hat Updated

High [CVE-2026-71491] Denial of Service via quadratic CPU consumption in comment grouping

Denial of Service via quadratic CPU consumption in comment grouping. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 7 more. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; and 3 more.

CVE-2026-71491
Unclassified
Aug 17, 2026
High7.5Red Hat Updated

High [CVE-2026-73646] Information disclosure via path traversal in source map auto-loading

Information disclosure via path traversal in source map auto-loading. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:50287 with package prometheus3-13-main-3.13.2-0.2.hum1, prometheus3-5-main-3.5.5-0.8.hum1. Affected products named by the advisory: Red Hat Hardened Images; Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; and 36 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; and 32 more.

CVE-2026-73646
Red Hat Enterprise Linux
Aug 17, 2026
High8.1Red Hat Updated

High [CVE-2026-19693] Arbitrary file write via symlink in archive

Arbitrary file write via symlink in archive. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Pipelines; OpenShift Service Mesh 3; and 13 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Ceph Storage 4; and 9 more.

CVE-2026-19693
Red Hat Enterprise Linux
Aug 17, 2026
High7.9Vendor: MediumRed Hat Updated

High [CVE-2026-15218] maas-api and maas-controller ServiceAccounts with excessive permissions lead to privilege escalation

maas-api and maas-controller ServiceAccounts with excessive permissions lead to privilege escalation. Red Hat rates this moderate (CVSS 7.9). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:60520 with package rhoai/odh-maas-api-rhel9:1787153683. Affected products named by the advisory: Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI).

CVE-2026-15218
Unclassified
Aug 17, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-64778] Visiting a maliciously crafted website may leak sensitive data

Visiting a maliciously crafted website may leak sensitive data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-200. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64778
Red Hat Enterprise Linux
Aug 17, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-73560] Server-Side Request Forgery and arbitrary file read via improper media processing

Server-Side Request Forgery and arbitrary file read via improper media processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-918. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-73560
Unclassified
Aug 17, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-71486] Denial of Service via unbounded token ID decoding

Denial of Service via unbounded token ID decoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-71486
Unclassified
Aug 17, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-59894] Arbitrary code execution via unescaped backslashes in generated snippets

Arbitrary code execution via unescaped backslashes in generated snippets. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 7 more. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; and 3 more.

CVE-2026-59894
Unclassified
Aug 17, 2026
Medium5.6Red Hat

Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service

Remote buffer overflow allows information disclosure or denial of service. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-120.

CVE-2026-19999
Unclassified
Aug 17, 2026
Medium6.3Red Hat

Medium [CVE-2026-19970] Remote heap-based buffer overflow vulnerability

Remote heap-based buffer overflow vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19970
Red Hat Enterprise Linux
Aug 17, 2026
Medium5.4Red Hat

Medium [CVE-2026-19969] Buffer overflow in 3DGS MDL7 model processing

Buffer overflow in 3DGS MDL7 model processing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19969
Red Hat Enterprise Linux
Aug 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-19968] Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser

Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19968
Red Hat Enterprise Linux
Aug 17, 2026
Medium6.3Red Hat

Medium [CVE-2026-19967] Heap-based buffer overflow in file decompression

Heap-based buffer overflow in file decompression. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19967
Red Hat Enterprise Linux
Aug 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-74579] fix mask build for partial field offload

fix mask build for partial field offload. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74579
Linux Kernel
Aug 17, 2026
Medium6.1Red Hat

Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal

Arbitrary file write via symlink following path traversal. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-59.

CVE-2026-74796
Unclassified
Aug 16, 2026
Medium5.9Red Hat

Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation

Sensitive information disclosure via static evaluation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-497.

CVE-2024-58375
Unclassified
Aug 16, 2026