Complete feed
Security advisories & CVEs
89 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation
Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.
Low [CVE-2026-54787] Signature bypass allows acceptance of bundles signed with expired keys
Signature bypass allows acceptance of bundles signed with expired keys. Red Hat rates this low (CVSS 3.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:44162 with package spire1-14-main-1.14.7-0.3.hum1, spire1-15-main-1.15.2-0.3.hum1, trivy-main-0.72.0-0.1.3.hum1.
Low [CVE-2026-18569] OIDC backchannel logout accepts unsigned forged logout tokens
OIDC backchannel logout accepts unsigned forged logout tokens. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.
Low [CVE-2026-18209] OIDC redirect_uri fragment bypass in HTTP parameter pollution check
OIDC redirect_uri fragment bypass in HTTP parameter pollution check. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1288.
Low [CVE-2026-18206] Client policy source-host wildcard domain matching bypass
Client policy source-host wildcard domain matching bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-20.
Low [CVE-2026-18217] SAML HTTP-Redirect binding response preserves query string leading to parameter pollution
SAML HTTP-Redirect binding response preserves query string leading to parameter pollution. Red Hat rates this moderate (CVSS 3.4). Weakness: CWE-20.
Low [CVE-2026-41709] ESX insufficient logging vulnerability
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.
Low [CVE-2026-59326] Spring Boot: The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment v…
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Low [CVE-2026-56847] Permission Model flaw allows trace logs to bypass filesystem write restrictions
Permission Model flaw allows trace logs to bypass filesystem write restrictions. Red Hat rates this low (CVSS 3.3). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.