Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.7Red Hat

Low [CVE-2026-57817] Authorization Code Substitution via missing c_hash validation

Authorization Code Substitution via missing c_hash validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5.

CVE-2026-57817
Unclassified
Aug 6, 2026
Low2.2Red Hat

Low [CVE-2026-18839] size_t underflow in singleOptionHelp

size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-18839
Unclassified
Aug 5, 2026
Low3.8Red Hat

Low [CVE-2026-70430] Privilege escalation via unrestricted object instantiation in project naming strategy configuration

Privilege escalation via unrestricted object instantiation in project naming strategy configuration. Red Hat rates this low (CVSS 3.8). Weakness: CWE-502. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-70430
Unclassified
Aug 5, 2026
Low2.3Apache

Low [CVE-2026-68980] Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset Identifier. The framework performed authorized based on the supplied Parameter Context Identifier without verifying the requested Identifier against the stored Identifier. Apache NiFi installations that do not implement different levels of authorization across Parameter Contexts are not subject to this vulnerability, because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.11.0 is the recommended mitigation, which verifies Parameter Context ownership of the requested Asset before deletion using the same strategy applied to Asset read operations.

CVE-2026-68980
NiFi
Aug 3, 2026
Low2.5Red Hat

Low [CVE-2026-18739] Off-by-one in poptStuffArgs

Off-by-one in poptStuffArgs. Red Hat rates this low (CVSS 2.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:56984 with package popt-main-1.19-11.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18739
Unclassified
Aug 3, 2026
Low3.3Red Hat

Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply

NSS responder uninitialized heap disclosure in initgroups reply. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908.

CVE-2026-68744
Unclassified
Aug 3, 2026
Low2.1Red Hat

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.

CVE-2026-66401
Unclassified
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection

Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67316
Unclassified
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation

Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.

CVE-2026-67294
Unclassified
Aug 1, 2026
Low3.1Red Hat

Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys

Signature bypass allows acceptance of bundles signed with expired keys. Red Hat rates this low (CVSS 3.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:44162 with package spire1-14-main-1.14.7-0.3.hum1, spire1-15-main-1.15.2-0.3.hum1, trivy-main-0.72.0-0.1.3.hum1.

CVE-2026-54787
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens

OIDC backchannel logout accepts unsigned forged logout tokens. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.

CVE-2026-18569
Unclassified
Jul 31, 2026
Low3.4Red Hat

Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check

OIDC redirect_uri fragment bypass in HTTP parameter pollution check. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1288.

CVE-2026-18209
Unclassified
Jul 31, 2026
Low3.7Red Hat

Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass

Client policy source-host wildcard domain matching bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-20.

CVE-2026-18206
Unclassified
Jul 31, 2026
Low3.4Vendor: MediumRed Hat

Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution

SAML HTTP-Redirect binding response preserves query string leading to parameter pollution. Red Hat rates this moderate (CVSS 3.4). Weakness: CWE-20.

CVE-2026-18217
Unclassified
Jul 31, 2026
Low2.7VMware

Low [CVE-2026-41709] ESX insufficient logging vulnerability

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41709
ESXiCloud FoundationvSphere
Jul 30, 2026
Low3.3VMware

Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-59326
Tanzu / Spring
Jul 30, 2026
Low3.3Red Hat

Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions

Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56847
Unclassified
Jul 30, 2026
Low2.8Red Hat

Low [CVE-2026-18018] Inappropriate implementation in Updater

Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).

CVE-2026-18018
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools

Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.

CVE-2026-18014
Unclassified
Jul 30, 2026
Low0.0Red Hat

Low [CVE-2026-18010] Inappropriate implementation in Passwords

Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.

CVE-2026-18010
Unclassified
Jul 30, 2026