Complete feed
Security advisories & CVEs
3323 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-45623] Information disclosure and denial of service via crafted CSS input
Information disclosure and denial of service via crafted CSS input. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54427 with package rhacm2/console-rhel9:1786547771.
High [CVE-2026-54272] Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification. Red Hat rates this moderate (CVSS 7.2). Weakness: CWE-918.
High [CVE-2026-54890] Denial of Service via integer underflow in ETF decoding
Denial of Service via integer underflow in ETF decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-59251] Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains
Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-55953] Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance
Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-55737] Denial of Service via crafted external term format binary
Denial of Service via crafted external term format binary. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-42792] Erlang OTP epmd: Remote Denial of Service via connection exhaustion
Erlang OTP epmd: Remote Denial of Service via connection exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-253. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-55971] Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow
Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:49716 with package thrift-0:0.24.0-1.el9ai, thrift-0:0.24.0-2.el9ai. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-55969] Denial of Service via integer overflow or wraparound
Denial of Service via integer overflow or wraparound. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785863006, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785442872, jaeger-main-2.20.0-0.5.hum1, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785443657.
High [CVE-2026-55968] Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation
Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-49158] Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.
High [CVE-2026-48586] Denial of Service via improper handling of highly compressed data
Denial of Service via improper handling of highly compressed data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:43799 with package opentelemetry-collector-main-0.157.0-0.1.hum1, jaeger-main-2.20.0-0.5.hum1, libthrift, loki3-7-main-3.7.4-0.1.hum1.
High [CVE-2026-45112] Denial of Service due to uncontrolled resource allocation
Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54776 with package libthrift.
High [CVE-2026-43871] Denial of Service via infinite loop
Denial of Service via infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.
High [CVE-2026-41608] Apache Thrift Python bindings: Denial of Service via data amplification
Apache Thrift Python bindings: Denial of Service via data amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:49837 with package thrift-main-0.24.0-0.1.hum1.
High [CVE-2026-17527] cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone
cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone. Red Hat rates this important (CVSS 7.7). Weakness: CWE-639. Affected products named by the advisory: Red Hat Container Native Virtualization 4.19; Red Hat Container Native Virtualization 4.20; Red Hat Container Native Virtualization 4.21; Red Hat OpenShift Virtualization 4; and 3 more.
High [CVE-2026-17523] can:bcm: arbitrary kernel code execution leading to escalate privileges
A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-15928] Cross-Site Scripting in error page component
Cross-Site Scripting in error page component. Red Hat rates this important (CVSS 7.4). Weakness: CWE-79.
High [CVE-2026-51300] Application crash and information leakage due to use-after-free
Application crash and information leakage due to use-after-free. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-51298] Denial of Service via use-after-free in JSON extraction
Denial of Service via use-after-free in JSON extraction. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.