Complete feed
Security advisories & CVEs
240 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation
Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.
Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys
Signature bypass allows acceptance of bundles signed with expired keys. Red Hat rates this low (CVSS 3.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:44162 with package spire1-14-main-1.14.7-0.3.hum1, spire1-15-main-1.15.2-0.3.hum1, trivy-main-0.72.0-0.1.3.hum1.
Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens
OIDC backchannel logout accepts unsigned forged logout tokens. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.
Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check
OIDC redirect_uri fragment bypass in HTTP parameter pollution check. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1288.
Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass
Client policy source-host wildcard domain matching bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-20.
Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution
SAML HTTP-Redirect binding response preserves query string leading to parameter pollution. Red Hat rates this moderate (CVSS 3.4). Weakness: CWE-20.
Low [CVE-2026-41709] ESX insufficient logging vulnerability
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.
Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions
Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
Low [CVE-2026-18018] Inappropriate implementation in Updater
Inappropriate implementation in Updater. Red Hat rates this low (CVSS 2.8).
Low [CVE-2026-18014] Insufficient validation of untrusted input in DevTools
Insufficient validation of untrusted input in DevTools. Red Hat rates this low. Weakness: CWE-434.
Low [CVE-2026-18010] Inappropriate implementation in Passwords
Inappropriate implementation in Passwords. Red Hat rates this low. Weakness: CWE-1021.
Low [CVE-2026-18007] Inappropriate implementation in Input
Inappropriate implementation in Input. Red Hat rates this low. Weakness: CWE-79.
Low [CVE-2026-18004] Insufficient policy enforcement in Speech
Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 3.2). Weakness: CWE-346.
Low [CVE-2026-18001] Inappropriate implementation in WebGL
Inappropriate implementation in WebGL. Red Hat rates this low (CVSS 3.1). Weakness: CWE-825.
Low [CVE-2026-18000] Insufficient policy enforcement in USB
Insufficient policy enforcement in USB. Red Hat rates this low (CVSS 2.8). Weakness: CWE-346.
Low [CVE-2026-17997] Inappropriate implementation in Passwords
Inappropriate implementation in Passwords. Red Hat rates this low (CVSS 2.4). Weakness: CWE-368.
Low [CVE-2026-17996] Inappropriate implementation in Browser
Inappropriate implementation in Browser. Red Hat rates this low (CVSS 3.9). Weakness: CWE-807.
Low [CVE-2026-17993] Race in Updater
Race in Updater. Red Hat rates this low (CVSS 3.9). Weakness: CWE-367.
Low [CVE-2026-17992] Uninitialized Use in Skia
Uninitialized Use in Skia. Red Hat rates this low. Weakness: CWE-824.