Complete feed
Security advisories & CVEs
3304 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-71267] Stack buffer overflow via overly long filenames
Stack buffer overflow via overly long filenames. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120.
High [CVE-2026-71235] Arbitrary Code Execution via Unrestricted Script Execution
Arbitrary Code Execution via Unrestricted Script Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59467 with package oadp/oadp-velero-rhel9:1786944540. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Compliance Operator; and 35 more. Affected products named by the advisory: Confidential Compute Attestation; Cryostat 4; Deployment Validation Operator; External Secrets Operator for Red Hat OpenShift; and 31 more.
High [CVE-2026-59679] Font Server Client encoding Out-Of-Bounds Read/Write
Font Server Client encoding[] Out-Of-Bounds Read/Write. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:55447 with package libXfont2-0:2.0.3-12.el9_8.3, libXfont2-0:2.0.3-12.el9_4.3, libXfont2-0:2.0.6-5.el10_2.3, libXfont2-0:2.0.3-12.el9_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2026-44950] Privilege Escalation via Heap Buffer Overflow in Font Server Client
Privilege Escalation via Heap Buffer Overflow in Font Server Client. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:55447 with package libXfont2-0:2.0.3-12.el9_8.3, libXfont2-0:2.0.3-12.el9_4.3, libXfont2-0:2.0.6-5.el10_2.3, libXfont2-0:2.0.3-12.el9_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2026-71202] Denial of Service via integer underflow in image cropping function
Denial of Service via integer underflow in image cropping function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-66274] Denial of Service via unbounded type nesting
Denial of Service via unbounded type nesting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 2 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat JBoss Enterprise Application Platform Expansion Pack.
High [CVE-2026-67589] Denial of Service via excessive memory allocation
Denial of Service via excessive memory allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat AMQ Clients.
High [CVE-2026-66273] Denial of Service due to excessive allocation
Denial of Service due to excessive allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-67588] Denial of Service via unbounded symbol value caching
Denial of Service via unbounded symbol value caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat AMQ Clients.
High [CVE-2026-66257] Denial of Service via unbounded symbol value caching
Denial of Service via unbounded symbol value caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-64572] free fib_alias with kfree_rcu on insert error path
free fib_alias with kfree_rcu() on insert error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-67863] Denial of Service via use-after-free vulnerability
Denial of Service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-67870] Denial of Service via incomplete validation in AddReferences
Denial of Service via incomplete validation in AddReferences. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.
High [CVE-2026-67869] Denial of Service via buffer overflow in Service_Call
Denial of Service via buffer overflow in Service_Call. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.
High [CVE-2026-64577] check skb_pull_data return in gtp1u_send_echo_resp
check skb_pull_data() return in gtp1u_send_echo_resp(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.
High [CVE-2026-64573] fix NVM tag length underflow in TLV parser
fix NVM tag length underflow in TLV parser. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64582] Fix a use-after-free problem in rxe_mmap
Fix a use-after-free problem in rxe_mmap. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-67864] Denial of Service via NodeManagement type-instantiation logic
Denial of Service via NodeManagement type-instantiation logic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287.
High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service
Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups
Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Red Hat lists fixing advisory RHSA-2026:59153 with package ansible-automation-platform-25/hub-rhel8:1787101922, ansible-automation-platform-26/lightspeed-rhel9:1787244079, python3.12-django-0:5.2.17-1.el8ap, ansible-automation-platform-25/lightspeed-rhel8:1787229385. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.