Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.1VMware Updated

Low [CVE-2026-59303] Spring Cloud: Dynamic destination cache size is not properly bound in Spring Cloud Stream.

Dynamic destination cache size is not properly bound in Spring Cloud Stream.

CVE-2026-59303
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59302] Spring Cloud: Potential for logging sensitive data in Spring Cloud Stream.

Potential for logging sensitive data in Spring Cloud Stream.

CVE-2026-59302
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59301] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function Azure.

Potential for logging sensitive data in Spring Cloud Function Azure.

CVE-2026-59301
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59300] Spring Cloud: Potential for logging sensitive data in Spring Cloud Function AWS.

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59300
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59299] Spring Cloud: Composition lookup can potentially poison base function in Spring Cloud Function.

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59299
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59298] Spring Cloud: Potential for improper filtering of HTTP headers in Spring Cloud Function.

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 3.2.16 and earlier

CVE-2026-59298
Tanzu / Spring
Aug 27, 2026
Low3.1VMware Updated

Low [CVE-2026-59297] Spring Cloud: Implementation of isSecure call of ServerlessHttpServletRequest does not verify the actual scheme.

Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3

CVE-2026-59297
Tanzu / Spring
Aug 27, 2026
Low2.0VMware Updated

Low [CVE-2026-59291] Spring Cloud: Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.

Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function.

CVE-2026-59291
Tanzu / Spring
Aug 27, 2026
Low3.7VMware Updated

Low [CVE-2026-59277] Spring Security: Spring Security's InetAddressMatchers utility provides matchInternal and matchExternal builders for constructing…

Spring Security's InetAddressMatchers utility provides matchInternal() and matchExternal() builders for constructing an InetAddressMatcher that classifies a given IP address as belonging to an internal (private) or external (public) network.

CVE-2026-59277
Tanzu / Spring
Aug 27, 2026
UnratedVMware Updated

Advisory [CVE-2026-59314] Spring Framework: Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response sp…

Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8

CVE-2026-59314
Tanzu / Spring
Aug 27, 2026
High7.4VMware Updated

High [CVE-2026-47841] Spring Security: application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a di…

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.

CVE-2026-47841
Tanzu / Spring
Aug 26, 2026
High7.2VMware Updated

High [CVE-2026-47836] Spring Cloud: The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repos…

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.14 and earlier

CVE-2026-47836
Tanzu / Spring
Aug 26, 2026
High7.3GitLab Updated

High [CVE-2026-18252] GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

CVE-2026-18252
Unclassified
Aug 26, 2026
High7.5Red Hat Updated

High [CVE-2026-80205] Denial of Service via unvalidated regular expressions

Denial of Service via unvalidated regular expressions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-80205
Unclassified
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80537] fix off-by-one in rtrefcount btree root level validation

fix off-by-one in rtrefcount btree root level validation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-80537
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80530] fix exchange-range reflink flag clearing issue with INO1_WRITTEN

fix exchange-range reflink flag clearing issue with INO1_WRITTEN. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80530
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80536] bounds-check buffer log item's dirty bitmap

bounds-check buffer log item's dirty bitmap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80536
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-74752] validate cookie AUTH state before use

validate cookie AUTH state before use. Red Hat rates this important (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74752
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-80522] tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req

tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req(). Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80522
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-74744] inherit needed_headroom and needed_tailroom from phy_dev

inherit needed_headroom and needed_tailroom from phy_dev. Red Hat rates this important (CVSS 7). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74744
Linux Kernel
Aug 26, 2026